Telnetd haavatavus, mis vÔimaldab root-Ôigustega sisselogimist ilma autentimiseta

GNU InetUtils telnetd server has a vulnerability that allows connection as any user, including the root user, without password verification. A CVE identifier has not yet been assigned. The vulnerability has existed since InetUtils version 1.9.3 (2015) and remains unfixed in the current release 2.7.0. A fix is available in the form of patches (1, 2).

The issue is due to the telnetd process using the utility "\/usr\/bin\/login" to check passwords, passing in the username specified by the client during connection to serveri. The "login" utility supports the "-f" option, which allows login without authentication (it is implied that this option is used when the user has already been authenticated). Thus, if one can substitute the "-f" option in the username, they can connect without password verification.

In a standard connection, using a username like "-f root" is not possible, but telnet has an autologin mode activated by the "-a" option. In this mode, the username is taken not from the command line but is passed through the environment variable USER. When the login utility is invoked, the value of this environment variable is substituted without further checks and without escaping special characters. Therefore, to connect as the root user, it is sufficient to set the environment variable USER to "-f root" and connect to the telnet server with the "-a" option: $ USER='-f root' telnet -a server_name

The change that led to the vulnerability was added to the telnetd code in March 2015 and was related to fixing a problem that did not allow the username to be determined in autologin mode without authentication in Kerberos. As a solution, support for passing the username for autologin mode through an environment variable was added, but they forgot to add the validation of the username from the environment variable.

Allikas: opennet.ru

Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid đŸ”„ Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid | ProHoster