|
Hole found in log-in function of Sun, IBM Unix
By Joris Evers (IDG) -- Attackers could get full access to servers running Unix versions supplied by Sun Microsystems Inc. and IBM because of a security hole in the log-in program of the operating system, experts warned Wednesday.
A buffer overflow flaw exists in the Unix log-in program, which authenticates access to the system with user names and passwords. Because the log-in program is also used by two programs remotely accessible, Telnet and rlogin (remote log-in), the flaw can be exploited even by those who don't have direct access to the system, experts at Internet Security Systems Inc. (ISS) in Atlanta and the (CERT Coordination Center) at Carnegie Mellon University in Pittsburgh said in separate statements. Systems are vulnerable only if Telnet, rlogin and other terminal connection services that use log-in for authentication are enabled, which they usually are by default, according to ISS. Attackers can exploit the vulnerability to gain super-user privileges or root access to the server, the highest privilege level on Unix systems, allowing the attacker to execute arbitrary commands. A software tool, or exploit, to compromise systems running the affected operating systems has been made public, according to ISS. ISS and CERT advise systems administrators to install Secure Shell (SSH), a secure alternative to Telnet and rlogin, and to disable default terminal connection services until the software can be patched. Sun and IBM have software fixes available, according to CC. Sun's Solaris 8 and earlier versions and IBM's AIX Versions 4.3 and 5.1 are affected. Other systems derived from the same code base, Unix System V, could also be vulnerable, said CERT/CC. Hewlett-Packard Co. told CERT that its HP-UX isn't exploitable. |
|
||||||||||||||||||||||||||||
|
RELATED IDG.net STORIES:
 CERT: Unix flaw could allow malicious hacking
(Computerworld)  Gokar worm spreads by e-mail, Web, chat (ITWorld.com)  Study: Constant security fixes overwhelming IT managers (Computerworld)  IBM unwraps first self-healing, self-managing products (InfoWorld.com)  Why your organization needs Linux (LinuxWorld)  IBM introducing entry-level two-way Unix server (Computerworld)  HP, Compaq fend off Unix server foes IBM, Sun (InfoWorld.com)  Tadpole takes backdoor into enterprise market (ITWorld.com) RELATED SITES:
 CERT Coordination Center
 Sun Microsystems  IBM Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.
TECHNOLOGY TOP STORIES:
Report: SUVs pose danger to cars New telemarketer tool trumps TeleZapper Terra Lycos logs $2.2B loss AOL to offer song downloads Microsoft seeks fiscal fountain of youth (More) |
||||||||||||||||||||||||||||||
| Back to the top |
© 2003 Cable News Network LP, LLLP.
A Time Warner Company. All Rights Reserved. Terms under which this service is provided to you. Read our privacy guidelines. Contact us. |