Skip to main content

Linux security backdoor

A recent article on Linux security showed that an old backdoor (cve-2007-4573), patched in kernel 2.6.22.7, has resurfaced.

Using the leak, any user that has a local user account on a 64 bit server, can easily get root rights, using the compatibility layer. While I don't fully understand the workings, I do understand that all OEL4/OEL5 64 bit servers are potentially harmed as they have kernels 2.6.9 and 2.6.18, resp. So I logged a SR on Metalink to see if I have a big security issue in the data center.

Update: CVE-2007-4573 has been renamed CVE-2010-3301 and RHEL states:
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5, and Red Hat Enterprise MRG, as they do not contain the upstream commit d4d67150 that introduced this flaw.

Update2: the issue is also listed as CVE-2010-3081, which is slightly different and Red Hat does track this one, as it affects RHEL5.

Update3: Ksplice has a test available to verify your system does not leave backdoors open, even after patching the exploit. Red Hat has issued a patch for its affected 64 bit systems.

Comments

Popular posts from this blog

Tuning the nscd name cache daemon

I've been playing a bit with the nscd now and want to share some tips related to tuning the nscd.conf file. To see how the DNS cache is doing, use nscd -g. nscd configuration: 0 server debug level 26m 57s server runtime 5 current number of threads 32 maximum number of threads 0 number of times clients had to wait yes paranoia mode enabled 3600 restart internal passwd cache: no cache is enabled [other zero output removed] group cache: no cache is enabled [other zero output removed] hosts cache: yes cache is enabled yes cache is persistent yes cache is shared 211 suggested size 216064 total data pool size 1144 used data pool size 3600 seconds time to live for positive entries 20 seconds time to live for negative entries 66254 cache hi...

Preventing PuTTY timeouts

Just found a great tip to prevent timeouts of PuTTY sessions. I'm fine with timeouts by the host, but in our case the firewall kills sessions after 30 minutes of inactivity... When using PuTTY to ssh to your Linux/Unix servers, be sure to use the feature to send NULL packets to prevent a timeout. I've set it to once every 900 seconds, i.e. 15 minutes... See screenshot on the right.

Logbook and Note Book

I'm no longer actively working with Linux although I use it privately. This was my work logbook during my job as a Linux Engineer and Architect for KPN Data Centers.  I'm keeping this as a log and note book. Who knows when it comes in handy although much will be outdated. If you find any good resources or more current howtos for what was written here, let me know!