Security Incidents mailing list archives
Re: sadmind hack?
From: bugtraq () NETWORKICE COM (Robert Graham)
Date: Thu, 13 Apr 2000 19:32:02 -0700
samind is certainly vulnerable on unpatched Solaris 2.6 machines. The exploit is difficult to get right because you have to know the appropriate offsets for the exact version (and configuration) of the victim system. Therefore, you often see multiple attempts in a row. Also, the service restarts automatically from inetd, so crashing a single instance doesn't stop the others from running. Rob. PS: Rule of thumb: If you have an unpatched Solaris 2.6 machine with RPC servers exposed to the Internet, there are a dozen different ways to break into the system. (Of course, same applies to older default installations of Linux and NT, so it is nothing special, but beware). -----Original Message----- From: Incidents Mailing List [mailto:INCIDENTS () securityfocus com]On Behalf Of Yip Chan Keong Sent: Wednesday, April 12, 2000 11:13 PM To: INCIDENTS () securityfocus com Subject: sadmind hack? I have gotten the following messages in my /var/adm/messages file on my solaris 2.6 host. is it a sign of break in? telnet and ftp on my host are limited by tcp wrappers. any idea how is the exploit made? Apr 12 06:43:34 xxxx inetd[138]: /usr/sbin/sadmind: Bus Error - core dumped Apr 12 06:43:36 xxxx inetd[138]: /usr/sbin/sadmind: Segmentation Fault - core dumped Apr 12 06:43:39 xxxx inetd[138]: /usr/sbin/sadmind: Bus Error - core dumped Apr 12 06:43:41 xxxx inetd[138]: /usr/sbin/sadmind: Segmentation Fault - core dumped Apr 12 06:43:44 xxxx inetd[138]: /usr/sbin/sadmind: Hangup many thanks and regards, /yck
Current thread:
- sadmind hack? Yip Chan Keong (Apr 12)
- Re: sadmind hack? Ex Machina (Apr 13)
- Re: sadmind hack? Robert Graham (Apr 13)
- Re: sadmind hack? Fyodor (Apr 16)
- Weird Ping requests Erick Brockway (Apr 16)
- Re: Weird Ping requests Richard Bejtlich (Apr 18)
- Re: Weird Ping requests Erick Brockway (Apr 21)
- Re: sadmind hack? Labu Labi (Apr 17)
- Re: sadmind hack? Prateek Jetly (Apr 18)
- Re: sadmind hack? Chad Roberts (Apr 14)
- Strange UDP traffic Ed Padin (Apr 14)
- Port 6502 Tony Lambiris (Apr 16)
- <Possible follow-ups>
- Re: sadmind hack? Oliver Friedrichs (Apr 13)