 |
ntop port allows remote and minor local compromise
Posted under
Security Advisory by
Ryan Troy
on Monday August 14th 2000 @ 05:52 PM MST
|
" If invoked in 'web' mode (ntop -w) then any remote user who can connect to the ntop server port (which is determined by local configuration) can execute arbitrary code on the server as the user running the ntop process, regardless of whether or not they can authenticate to the ntop server by providing a valid username and password."
|
|
|
proftpd port contains remote root compromise
Posted under
Security Advisory by
Ryan Troy
on Monday August 14th 2000 @ 05:21 PM MST
|
II. Problem Description
The proftpd port, versions prior to 1.2.0rc2, contains a vulnerability which allows FTP users, both anonymous FTP users and those with a valid account, to execute arbitrary code as root on the local machine, by inserting string-formatting operators into command input, which are incorrectly parsed by the FTP server.
This is the same class of vulnerability as the one described in FreeBSD Security Advisory 00:29, which pertained to the wu-ftpd port.
The proftpd port is not installed by default, nor is it "part of FreeBSD" as such: it is part of the FreeBSD ports collection, which
contains nearly 3700 third-party applications in a ready-to-install format. The ports collections shipped with FreeBSD 3.5 contains this
problem since it was discovered after the release, but FreeBSD 4.1 did not ship with the proftpd package (and the port was disabled to
prevent building) because the vulnerability was known but not yet fixed.
FreeBSD makes no claim about the security of these third-party applications, although an effort is underway to provide a security
audit of the most security-critical ports.
|
|
|
dhclient vulnerable to malicious dhcp server
Posted under
Security Advisory by
Ryan Troy
on Monday August 14th 2000 @ 05:11 PM MST
|
New Security Advisory
The dhclient utility (DHCP client), versions 2.0pl2 and before (for the version 2.x series), and versions 3.0b1pl16 and before
(for the version 3.x series) does not correctly validate input from the server, allowing a malicious DHCP server to execute arbitrary commands as root
on the client. DHCP may be enabled if your system was initially configured from a DHCP server at install-time, or if you have
specifically enabled it after installation.
FreeBSD 4.1 is not affected by this problem since it contains the 2.0pl3 client.
|
|
|
LinuxWorld Conference To Open
Posted under
Linux by
Ryan Troy
on Monday August 14th 2000 @ 09:23 AM MST
|
SAN JOSE, Calif. (AP) - As the new kid on the block, the Linux computer operating system once had few friends besides the stereotypical technology geek whose idea of fun was spending hours rewriting software code.
But as that same kid begins to gather dozens of new electronic toys around it, Linux has suddenly become part of the in crowd - and an increasing threat to Microsoft Corp.'s (NasdaqNM:MSFT - news) Windows monopoly.
Read the Article at Yahoo
|
|
|
Maximumbsd News
Posted under
Announcements by
Ryan Troy
on Saturday August 12th 2000 @ 03:16 PM MST
|
Site news:
We now have a section for FreeBSD downloads you can check it out over on the side menu under features. Also check out the FreeBSD Mirrors page it has been updated and reformated.
You can know have Maximumbsd news on your Website or My Netscape Channel for information go here.
|
|
|
|
 |
|