AplusWebMaster
Topic Starter
FYI…
- http://www.kb.cert.org/vuls/id/881872
2/12/2007
"I. Description
The Sun Solaris telnet daemon may accept authentication information via the USER environment variable. However, the Sun Solaris telnet daemon fails to properly sanitize this authentication information before passing it to the login program. This may allow a remote attacker to bypass the Sun Solaris telnet daemon's authentication mechanisms. In default configurations of Solaris this vulnerability cannot be exploited to gain access to the root account, but any existing non-root account can be leveraged in attacks targeting this vulnerability… Sun Solaris 8 and 9 are not affected by this issue.
II. Impact
A remote attacker with knowledge of existing user accounts could log on to a vulnerable system via the Sun Solaris telnet daemon and gain elevated privileges.
III. Solution
We are unaware of a solution to this problem. Until a solution becomes available, the following workarounds are strongly encouraged:
> Disable telnet if it's not needed. Telnet can be disabled by issuing the following command:
# svcadm disable telnet
Restrict access
You may wish to block access to the vulnerable software from outside your network perimeter, specifically by blocking access to the ports used by Sun Solaris telnet (typically 23/tcp). This will limit your exposure to attacks.
Prefer SSH over telnet
SSH provides a comparatively more secure method for remotely logging into a system than telnet. As general advice, we recommend using SSH rather than telnet…"
> http://isc.sans.org/diary.html?storyid=2220
Last Updated: 2007-02-12 21:37:54 UTC
.
- http://www.kb.cert.org/vuls/id/881872
2/12/2007
"I. Description
The Sun Solaris telnet daemon may accept authentication information via the USER environment variable. However, the Sun Solaris telnet daemon fails to properly sanitize this authentication information before passing it to the login program. This may allow a remote attacker to bypass the Sun Solaris telnet daemon's authentication mechanisms. In default configurations of Solaris this vulnerability cannot be exploited to gain access to the root account, but any existing non-root account can be leveraged in attacks targeting this vulnerability… Sun Solaris 8 and 9 are not affected by this issue.
II. Impact
A remote attacker with knowledge of existing user accounts could log on to a vulnerable system via the Sun Solaris telnet daemon and gain elevated privileges.
III. Solution
We are unaware of a solution to this problem. Until a solution becomes available, the following workarounds are strongly encouraged:
> Disable telnet if it's not needed. Telnet can be disabled by issuing the following command:
# svcadm disable telnet
Restrict access
You may wish to block access to the vulnerable software from outside your network perimeter, specifically by blocking access to the ports used by Sun Solaris telnet (typically 23/tcp). This will limit your exposure to attacks.
Prefer SSH over telnet
SSH provides a comparatively more secure method for remotely logging into a system than telnet. As general advice, we recommend using SSH rather than telnet…"
> http://isc.sans.org/diary.html?storyid=2220
Last Updated: 2007-02-12 21:37:54 UTC
.