Date: Fri, 17 Dec 2004 17:08:33 +0100 (CET) From: Richard Kojedzinszky <krichy@tvnetwork.hu> To: Jerry Bell <jerry@syslog.org> Cc: freebsd-security@freebsd.org Subject: re: Strange command histories in hacked shell server Message-ID: <Pine.LNX.4.58.0412171706020.14819@krichy.tvnetwork.hu> In-Reply-To: <2641.209.134.164.137.1103298695.squirrel@209.134.164.137> References: <2641.209.134.164.137.1103298695.squirrel@209.134.164.137>
next in thread | previous in thread | raw e-mail | index | archive | help
DEar all, if you do su, uid and euid changes together. but when you issue passwd, a setuid root, uid remains your uid, that is where passwd knows who is executing him. Kojedzinszky Richard TvNetWork Rt. E-mail: krichy@tvnetwork.hu PGP: 0x24E79141 Fingerprint = 6847 ECFF EF58 0C09 18A5 16CF 270F 0C6F 24E7 9141 On Fri, 17 Dec 2004, Jerry Bell wrote: > Did I understand correctly, that anyone can connect to the shell server > and create an account for themselves? > > I have a somewhat rudimentry hardening guide for FreeBSD at > http://www.syslog.org/Content-5-4.phtml > I've tried to keep it up-to-date, but I have yet to incorporate MAC, which > I think will help out a good bit more. > > I hope you find this a useful. > > Jerry > http://www.syslog.org > > Ganbold <ganbold <at> micom.mng.net> wrote: > >Please give me some advice and info regarding this kind of hack. > >What should I do in order to secure my shell server? I mean except > >securelevel, unneeded services etc. > >Can somebody give me some hints on file and directory permissions? > >Is there anybody who has similar server config and already had such issues > >and problems? > > > _______________________________________________ > freebsd-security@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org" >
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.LNX.4.58.0412171706020.14819>