Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 17 Dec 2004 17:08:33 +0100 (CET)
From:      Richard Kojedzinszky <krichy@tvnetwork.hu>
To:        Jerry Bell <jerry@syslog.org>
Cc:        freebsd-security@freebsd.org
Subject:   re: Strange command histories in hacked shell server
Message-ID:  <Pine.LNX.4.58.0412171706020.14819@krichy.tvnetwork.hu>
In-Reply-To: <2641.209.134.164.137.1103298695.squirrel@209.134.164.137>
References:  <2641.209.134.164.137.1103298695.squirrel@209.134.164.137>

next in thread | previous in thread | raw e-mail | index | archive | help
DEar all,

if you do su, uid and euid changes together. but when you issue passwd, a
setuid root, uid remains your uid, that is where passwd knows who is
executing him.

Kojedzinszky Richard
TvNetWork Rt.
E-mail: krichy@tvnetwork.hu
PGP: 0x24E79141
  Fingerprint = 6847 ECFF EF58 0C09 18A5  16CF 270F 0C6F 24E7 9141

On Fri, 17 Dec 2004, Jerry Bell wrote:

> Did I understand correctly, that anyone can connect to the shell server
> and create an account for themselves?
>
> I have a somewhat rudimentry hardening guide for FreeBSD at
> http://www.syslog.org/Content-5-4.phtml
> I've tried to keep it up-to-date, but I have yet to incorporate MAC, which
> I think will help out a good bit more.
>
> I hope you find this a useful.
>
> Jerry
> http://www.syslog.org
>
> Ganbold <ganbold <at> micom.mng.net> wrote:
> >Please give me some advice and info regarding this kind of hack.
> >What should I do in order to secure my shell server? I mean except
> >securelevel, unneeded services etc.
> >Can somebody give me some hints on file and directory permissions?
> >Is there anybody who has similar server config and already had such issues
> >and problems?
>
>
> _______________________________________________
> freebsd-security@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
>



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.LNX.4.58.0412171706020.14819>