Results 1 to 4 of 4

Thread: KNOPPIX CD Default Install May Let Local Users Grab Root

  1. #1
    Member registered user
    Join Date
    Nov 2002
    Posts
    85

    KNOPPIX CD Default Install May Let Local Users Grab Root

    http://www.securitytracker.com/alert...l/1007142.html

    KNOPPIX CD Default Configuration May Let Local Users Grab Root Privileges
    SecurityTracker Alert ID: 1007142
    CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site)
    Date: Jul 9 2003
    Impact: Modification of system information, Modification of user information, Root access via local system
    Exploit Included: Yes
    Description: A vulnerability was reported in the default configuration of the KNOPPIX CD. A local user can obtain root privileges.

    It is reported that the "knx-hdinstall" default configuration creates unsafe temporary files in the '/tmp/.qt/' directory: 'qt_plugins_3.0rc', and 'qt_plugins_3.0rc.lock'. A local user can create a symbolic link (symlink) from a critical file on the system to one of these temporary files. Then, when a target user logs in, the symlinked file will be overwritten with the privileges of the target user, potentially including the root user.
    Impact: A local user can cause a target user to overwrite a file on the system with the privileges of the target user. This can be exploited by a local user to potentially obtain root privileges.

    Solution: No solution was available at the time of this entry.
    Vendor URL: www.knoppix.org/ (Links to External Site)
    Cause: Access control error, State error
    Reported By: Hugo "Vazquez" "Carames" <overclocking_a_la_abuela@hotmail.com>
    Message History: None.

  2. #2
    Junior Member
    Join Date
    Jun 2003
    Posts
    9
    as a newby (and a root on a hd installed- Knoppix) What's the sollution to prevent this???

  3. #3
    Junior Member
    Join Date
    Jul 2003
    Posts
    2
    I installed with an older build of 3.2 and have no such directory.

  4. #4
    Senior Member registered user
    Join Date
    Mar 2003
    Location
    Cleveland, OH
    Posts
    228
    The solution is to reboot your pc... all user created files in /tmp will be deleted, even on a hard drive install.

    This is (IMHO) a very LOW risk (but one I want to be aware of regardless). Here's why I would consider this low risk: you need local (hands on) access to install or use knoppix from a cd anyways! When you have physical access, and boot from a knoppix cd, root access is readily available. After you do a hard drive install and reboot, the system security is only going to be as good as your setup guarding against know vulnerabilities.

    My two cents, and worth every penny.

    ~paul

Similar Threads

  1. knoppix 3.3 'default' root passwd???
    By Cerebrus in forum General Support
    Replies: 4
    Last Post: 06-21-2004, 01:49 PM
  2. Stange Login + Default Users
    By jeremymeindl in forum Hdd Install / Debian / Apt
    Replies: 1
    Last Post: 05-29-2004, 01:06 AM
  3. Cannot start X under any users other than root
    By pizarra in forum Hdd Install / Debian / Apt
    Replies: 2
    Last Post: 03-23-2004, 06:01 PM
  4. help Give users root access
    By warpedmind in forum General Support
    Replies: 12
    Last Post: 11-19-2003, 12:10 AM
  5. OpenOffice non Root or Knoppix Users
    By rec9140 in forum General Support
    Replies: 0
    Last Post: 09-19-2003, 07:21 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


Dell R730xd 12LFF 2.6Ghz 20-C 128GB H730 2x10G+2x1G NIC 2x1100W 12x Trays Rails picture

Dell R730xd 12LFF 2.6Ghz 20-C 128GB H730 2x10G+2x1G NIC 2x1100W 12x Trays Rails

$721.05



Dell Poweredge R640 Server | 2x Silver 4114 20 Cores | 64GB | 8x HDD Trays picture

Dell Poweredge R640 Server | 2x Silver 4114 20 Cores | 64GB | 8x HDD Trays

$1614.99



Dell Poweredge R640 Server | 2x Silver 4114 20 Cores | 16GB | 2x HDD Trays picture

Dell Poweredge R640 Server | 2x Silver 4114 20 Cores | 16GB | 2x HDD Trays

$1349.99



Dell PowerEdge R7525 Server 24X2.5(8XNVME)+H745 2xEPYC 7302 CPU 128G RAM 2x2400W picture

Dell PowerEdge R7525 Server 24X2.5(8XNVME)+H745 2xEPYC 7302 CPU 128G RAM 2x2400W

$3350.00



Dell PowerEdge R730XD 28 Core Server 2X Xeon E5-2680 V4 H730 128GB RAM No HDD picture

Dell PowerEdge R730XD 28 Core Server 2X Xeon E5-2680 V4 H730 128GB RAM No HDD

$389.99



HP Proliant DL360 Gen9 28 Core SFF Server 2X E5-2680 V4 16GB RAM P440ar No HDD picture

HP Proliant DL360 Gen9 28 Core SFF Server 2X E5-2680 V4 16GB RAM P440ar No HDD

$196.95



Dell PowerEdge R720XD Xeon E5-2680 V2 2.8GHz 20 Cores 256GB RAM 12x4TB picture

Dell PowerEdge R720XD Xeon E5-2680 V2 2.8GHz 20 Cores 256GB RAM 12x4TB

$510.00



Dell PowerEdge R620 Server 2x E5-2660 v1 2.2GHz 16 Cores 256GB RAM 2x 300GB HDD picture

Dell PowerEdge R620 Server 2x E5-2660 v1 2.2GHz 16 Cores 256GB RAM 2x 300GB HDD

$79.19



DELL PowerEdge R730 Server 2x E5-2680v4 2.4GHz =28 Cores 32GB H730 4xRJ45 picture

DELL PowerEdge R730 Server 2x E5-2680v4 2.4GHz =28 Cores 32GB H730 4xRJ45

$284.00



HP ProLiant DL380 Gen9 16SFF 2x E5-2680v4 2.4GHz =28 Cores 64GB P840 4xRJ45 picture

HP ProLiant DL380 Gen9 16SFF 2x E5-2680v4 2.4GHz =28 Cores 64GB P840 4xRJ45

$353.00