Sat Dec 18 13:05:55 2004 New Samba
exploit
Posted by Tony Lawrence
Search Keys: security
Referencing:
http://cert.uni-stuttgart.de/archive/bugtraq/2004/12/msg00186.html
Patches from http://us2.samba.org/samba/ftp/patches/security/
This of course does require access to a share to begin with, and not too many folks expose shares to the big bad world. However, this could allow someone who had gained internal access through hacking a non-admin account to escalate their privilege and get root access to the Samba server, so it's important to patch this one.
It never ends, does it? And it is particularly galling to we Unixy folks because the only reason we have any Samba running at all is because we need it for the darn Microsoft machines. I think it's a fair observation that NFS wasn't much used in smaller Unix systems, but Network Neighborhood is everywhere.
It all goes back to "making it easy". The easier you make it for the users, the more places where a mistake like this can bite you.
Oh well, patch and get on with it, right?
Enter your email address for automatic notification of new posts here
(be sure to whitelist 'feedburner.com' if you use spam filtering)
| Views for this page | ||||
|---|---|---|---|---|
| Today | This Week | This Month | This Year | Overall |
| 3 | 6 | 13 | 13 | 3,506 |
Have you tried Searching this site?
Unix/Linux/Mac OS X support by phone, email or on-site: Support Rates
This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more. We appreciate comments and article submissions.
Publish your articles, comments, book reviews or opinions here!
Click here to add your comments