ignore security and it'll go away

su+pam.redhat.txt

su+pam.redhat.txt
Posted Aug 17, 1999

Red Hat PAM version of the 'su' utility allows any local user to easily brute force the superuser (root) password with fast scripted (automated) attacks, avoiding all logging via syslog too.

tags | exploit, local, root
systems | linux, redhat
MD5 | 3f04992bddafdcbbd5879448eb4d28fc

su+pam.redhat.txt

Change Mirror Download
Date: Wed, 9 Jun 1999 14:07:27 -0700
From: Tani Hosokawa <unknown@RIVERSTYX.NET>
To: BUGTRAQ@netspace.org
Subject: vulnerability in su/PAM in redhat

I was talking to some guy on IRC (st2) and he asked me to mention to
bugtraq (because he's not on the list) that the PAMified su that comes
with redhat has a slight hole. When you try to su to root (for example) if
it's successful, immediately gives you a shell prompt. Otherwise, it
delays a full second, then logs an authentication failure to syslog. If
you hit break in that second, no error, plus you know that the password
was bad, so you can brute force root's password. I wrote a little
threaded Perl prog that tested it (with a 0.25 second delay before the
break) to attack my own password (with my password in the wordlist) and it
seemed to work just fine, even with my own password hundreds of words down
in the list, so it seems pretty predictable, as long as the server's under
very little load (else you get a delay no matter what, and it screws the
whole process by giving false negatives).

---
tani hosokawa
river styx internet

-------------------------------------------------------------------------

Date: Fri, 11 Jun 1999 11:43:59 -0700
From: Tani Hosokawa <unknown@RIVERSTYX.NET>
To: BUGTRAQ@netspace.org
Subject: Re: vulnerability in su/PAM in redhat

Well, I just checked it out on a fairly vanilla RH6.0 box, and it
exhibited the same behaviour. This is only a bug with PAM-enabled
machines, Slackware, etc. do not have this problem. Also, it exhibits
this behaviour with or without shadowed passwords (I pwunconv'd and tried
it just now, same thing happened). I think it's a problem with one of the
PAM modules.

On Fri, 11 Jun 1999, C.J. Oster wrote:

> Not if you have the latest shadow package installed. If you type in an
> incorrect password, you get an immediate 'Sorry.' This may be correct for
> earlier versions of the shadow suite, but I don't remember and I only have
> the newest one installed. Latest version is at
> ftp://ftp.ists.pwr.wroc.pl/pub/linux/shadow/
> >I was talking to some guy on IRC (st2) and he asked me to mention to
> >bugtraq (because he's not on the list) that the PAMified su that comes
> >with redhat has a slight hole. When you try to su to root (for example) if
> >it's successful, immediately gives you a shell prompt. Otherwise, it
> >delays a full second, then logs an authentication failure to syslog. If
> >you hit break in that second, no error, plus you know that the password
> >was bad, so you can brute force root's password. I wrote a little
> >threaded Perl prog that tested it (with a 0.25 second delay before the
> >break) to attack my own password (with my password in the wordlist) and it
> >seemed to work just fine, even with my own password hundreds of words down
> >in the list, so it seems pretty predictable, as long as the server's under
> >very little load (else you get a delay no matter what, and it screws the
> >whole process by giving false negatives).

---
tani hosokawa
river styx internet

-------------------------------------------------------------------------

Date: Fri, 11 Jun 1999 12:38:02 +0000
From: Javi Polo <javipolo@infomail.lacaixa.es>
To: BUGTRAQ@netspace.org
Subject: Re: vulnerability in su/PAM in redhat

On Wed, 9 Jun 1999, Tani Hosokawa wrote:

> with redhat has a slight hole. When you try to su to root (for example) if
> it's successful, immediately gives you a shell prompt. Otherwise, it
> delays a full second, then logs an authentication failure to syslog. If
> you hit break in that second, no error, plus you know that the password
> was bad, so you can brute force root's password. I wrote a little

Checked ....
Confirmed for su that comes with
sh-utils-1.16-14
and using
pam-0.64-3

Ta luegos ...... Oh my God! They killed Kenny!!!!!!
Javi Polo ;)
Me puedes encontrar en fido en 2:347/13.4 yo tambiƩn 3000ya.com
AUTOPISTA NO!!!!!!!!!!! No a l'autopista de llevant

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close