SECURITY: Easy Rootkit Crontab Exploit Found

Posted by Tracer on Jul 19, 2006 1:24 PM EDT
securityfocus.com; By Tracer/Supermike
Mail this story
Print this story

This rootkit affects kernels 2.6.17.4 or earlier. On the Solution tab: The vendor has released kernel version 2.6.17.4 to address this issue.

This is the rootkit used to get into the Debian servers the other day by a malicious cracker posing as a Debian developer (in order to get shell access). It affects almost all popular distros, however.

* Requires at least local shell access before one can be hacked with the rootkit.

* Operates through an exploit activated by user's crontab that causes a coredump and root connectivity. Not quite clear how that works, but you can see the C source on the link above if you click the Exploit tab.

Fix appears to be:

* Remove 'gcc' if you don't use it.

* Linux kernel versions prior to 2.6.17.4 are vulnerable. Pressure your distro provider for a patch if they don't have one already. (I'm on Ubuntu Breezy 5.10 and kernel 2.6.12-10-686, so I'm at risk until Ubuntu decides to have a patch for existing kernels or releases a kernel update.)

* If someone's running an old version of Linux that may not have been tested, they should probably try the various versions of the exploit code and see if can be achieved on their systems. Lord help the person who still wants to run something like Red Hat 7 or something like that.

Full Story

  Nav
» Read more about: Story Type: News Story, Security; Groups: Community, Debian, Fedora, Kernel, Linux, LXer, Mandriva, Red Hat, Slackware, SUSE, Ubuntu

« Return to the newswire homepage

Subject Topic Starter Replies Views Last Post
I hope everyone is paying attention! jimf 14 1,454 Jul 19, 2006 8:22 PM

You cannot post until you login.