exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

xandros-autorun.txt

xandros-autorun.txt
Posted Jun 3, 2002
Authored by dotslash@snosoft.com | Site snosoft.com

A vulnerability in the Xandros Linux autorun utility can be used to disclose parts of protected files such as /etc/shadow.

tags | exploit
systems | linux
SHA-256 | 82784ea64ae0545645c2ce9fc64d6aed90906eec891e5e934434f6621cad4670

xandros-autorun.txt

Change Mirror Download
There is a new debian based distro called Xandros making its way on to the market.I believe the developers from Corel Linux are on board with Xandros. It has at least one public beta and another
on the way and I know of at least one OS that uses it as its backend. I got a chance to play on a couple of Xandros based distros and came up with a few security issues.

Due to some extremely sketchy wording on disclosure by one of the above mentioned distros I will refrence all distros in general as a "Xandros based flavor of linux". I can not verify that the
holes are shared in all flavors.

The first issue I am going to disclose is in the setuid autorun binary. If this binary is called with the command line argument -c and any file name you are able to read the first line of that
file... for example /etc/shadow.

exploit: autorun -c /etc/shadow

Here is part of the response from the developer regarding only this issue... I just informed them of 6 others that I am aware of.

---------- Author or Developers response ----------------

I have fixed the bug in autorun. There will be a new package posted
for Xandros Desktop Beta 2. A fix for Beta 1 will not be provided as we
are not supporting older beta releases in any way. Lindows.com has been
notified as well, but we have yet to hear back from them.

As soon as our QA department gives us the green light, a notice will be
posted to the beta newsgroups and the new package will be posted on the
ftp site.
---------------------------------------------------------

http://www.snosoft.com
-KF
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close