Results 1 to 4 of 4

Thread: KNOPPIX CD Default Install May Let Local Users Grab Root

  1. #1
    Member registered user
    Join Date
    Nov 2002
    Posts
    85

    KNOPPIX CD Default Install May Let Local Users Grab Root

    http://www.securitytracker.com/alert...l/1007142.html

    KNOPPIX CD Default Configuration May Let Local Users Grab Root Privileges
    SecurityTracker Alert ID: 1007142
    CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site)
    Date: Jul 9 2003
    Impact: Modification of system information, Modification of user information, Root access via local system
    Exploit Included: Yes
    Description: A vulnerability was reported in the default configuration of the KNOPPIX CD. A local user can obtain root privileges.

    It is reported that the "knx-hdinstall" default configuration creates unsafe temporary files in the '/tmp/.qt/' directory: 'qt_plugins_3.0rc', and 'qt_plugins_3.0rc.lock'. A local user can create a symbolic link (symlink) from a critical file on the system to one of these temporary files. Then, when a target user logs in, the symlinked file will be overwritten with the privileges of the target user, potentially including the root user.
    Impact: A local user can cause a target user to overwrite a file on the system with the privileges of the target user. This can be exploited by a local user to potentially obtain root privileges.

    Solution: No solution was available at the time of this entry.
    Vendor URL: www.knoppix.org/ (Links to External Site)
    Cause: Access control error, State error
    Reported By: Hugo "Vazquez" "Carames" <overclocking_a_la_abuela@hotmail.com>
    Message History: None.

  2. #2
    Junior Member
    Join Date
    Jun 2003
    Posts
    9
    as a newby (and a root on a hd installed- Knoppix) What's the sollution to prevent this???

  3. #3
    Junior Member
    Join Date
    Jul 2003
    Posts
    2
    I installed with an older build of 3.2 and have no such directory.

  4. #4
    Senior Member registered user
    Join Date
    Mar 2003
    Location
    Cleveland, OH
    Posts
    228
    The solution is to reboot your pc... all user created files in /tmp will be deleted, even on a hard drive install.

    This is (IMHO) a very LOW risk (but one I want to be aware of regardless). Here's why I would consider this low risk: you need local (hands on) access to install or use knoppix from a cd anyways! When you have physical access, and boot from a knoppix cd, root access is readily available. After you do a hard drive install and reboot, the system security is only going to be as good as your setup guarding against know vulnerabilities.

    My two cents, and worth every penny.

    ~paul

Similar Threads

  1. knoppix 3.3 'default' root passwd???
    By Cerebrus in forum General Support
    Replies: 4
    Last Post: 06-21-2004, 01:49 PM
  2. Stange Login + Default Users
    By jeremymeindl in forum Hdd Install / Debian / Apt
    Replies: 1
    Last Post: 05-29-2004, 01:06 AM
  3. Cannot start X under any users other than root
    By pizarra in forum Hdd Install / Debian / Apt
    Replies: 2
    Last Post: 03-23-2004, 06:01 PM
  4. help Give users root access
    By warpedmind in forum General Support
    Replies: 12
    Last Post: 11-19-2003, 12:10 AM
  5. OpenOffice non Root or Knoppix Users
    By rec9140 in forum General Support
    Replies: 0
    Last Post: 09-19-2003, 07:21 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


1U Supermicro Server 10 Bay 2x Intel Xeon 3.3Ghz 8C 128GB RAM 480GB SSD 2x 10GBE picture

1U Supermicro Server 10 Bay 2x Intel Xeon 3.3Ghz 8C 128GB RAM 480GB SSD 2x 10GBE

$297.00



HP/HPE ProLiant AMD Opteron X3216 APU 16 GB RAM MicroServer Gen 10 NO DRIVES picture

HP/HPE ProLiant AMD Opteron X3216 APU 16 GB RAM MicroServer Gen 10 NO DRIVES

$299.99



HP ProLiant Xeon E3-1220L V2 MicroServer Gen8 2.30 GHz 16 GB RAM NO DRIVES picture

HP ProLiant Xeon E3-1220L V2 MicroServer Gen8 2.30 GHz 16 GB RAM NO DRIVES

$199.99



HP ProLiant HSTNS-5151 Micro Server 8GB RAM No Drives/Key/Caddies *READ* picture

HP ProLiant HSTNS-5151 Micro Server 8GB RAM No Drives/Key/Caddies *READ*

$94.99



SuperMicro Server 505-2 Intel Atom 2.4GHz 8GB RAM SYS-5018A-FTN4 1U Rackmount picture

SuperMicro Server 505-2 Intel Atom 2.4GHz 8GB RAM SYS-5018A-FTN4 1U Rackmount

$202.49



HPE ProLiant MicroServer Gen10 Plus v2 Ultra Micro Tower Server - 1 x Intel Xeon picture

HPE ProLiant MicroServer Gen10 Plus v2 Ultra Micro Tower Server - 1 x Intel Xeon

$846.19



HP ProLiant Xeon E3-1220L V2 2.30 GHz 16 GB RAM MicroServer Gen8 NO DRIVES picture

HP ProLiant Xeon E3-1220L V2 2.30 GHz 16 GB RAM MicroServer Gen8 NO DRIVES

$199.99



Supermicro 5018A-FTN4 Rack Server - Black picture

Supermicro 5018A-FTN4 Rack Server - Black

$125.00



2U 12 Bay SAS3 SuperMicro Server 6028U-TR4T+ W/ X10DRU-i+ Barebone 12 Caddy RAIL picture

2U 12 Bay SAS3 SuperMicro Server 6028U-TR4T+ W/ X10DRU-i+ Barebone 12 Caddy RAIL

$299.00



Supermicro 505-2 Mini-1U Server 5018A-FTN4 16GB 2.4ghz Atom + Rack Ears picture

Supermicro 505-2 Mini-1U Server 5018A-FTN4 16GB 2.4ghz Atom + Rack Ears

$199.00