Great Circle Associates Firewalls
(February 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Can you print from a chroot'd process?
From: Icarus Sparry <I . Sparry @ ss1 . bath . ac . uk>
Date: Sat, 12 Feb 94 20:03:41 GMT
To: George Hartzell <hartzell @ edu . berkeley . cs>
Cc: mjr @ tis . com, Firewalls @ greatcircle . com, johng @ weema . chi . uwa . edu . au
Reply-to: I . Sparry @ bath . ac . uk

(Put lpr into the chrooted environment)
>What's so ugly about this

Well, look how many security related patches Sun have issued for lpr.
2 years ago many of the UK academic computers running Unix were cracked
as root, using lpd. The ability to overwrite any file in the system is
a powerful tool to the cracker.

OB CERT bash - They still have not issued a warning about this.


Follow-Ups:
Indexed By Date Previous: Re: Can you print from a chroot'd process?
From: George Hartzell <hartzell @ postgres . Berkeley . EDU>
Next: Re: Can you print from a chroot'd process?
From: Jim Duncan <jim @ math . psu . edu>
Indexed By Thread Previous: Re: Can you print from a chroot'd process?
From: George Hartzell <hartzell @ postgres . Berkeley . EDU>
Next: Re: Can you print from a chroot'd process?
From: Jim Duncan <jim @ math . psu . edu>

Google
 
Search Internet Search www.greatcircle.com