BugTraq
Solaris telnet vulnberability - how many on your network? Feb 12 2007 06:00AM
Gadi Evron (ge linuxbox org) (2 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 14 2007 10:41AM
Leandro Gelasi (leandro gelasi tiscali it)
RE: Solaris telnet vulnberability - how many on your network? Feb 13 2007 06:10AM
Oliver Friedrichs (oliver_friedrichs symantec com) (2 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 13 2007 06:11PM
Casper Dik Sun COM (1 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 13 2007 08:49PM
Gadi Evron (ge linuxbox org) (1 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 13 2007 08:53PM
Casper Dik Sun COM (1 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 13 2007 08:56PM
Gadi Evron (ge linuxbox org) (2 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 13 2007 09:00PM
Casper Dik Sun COM (1 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 14 2007 12:16AM
Joe Shamblin (wjs cs duke edu) (3 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 15 2007 06:51AM
Darren Reed (avalon caligula anu edu au)
RE: [Full-disclosure] Solaris telnet vulnberability - how many onyour network? Feb 14 2007 02:25PM
David Taylor (ltr isc upenn edu)
Re: Solaris telnet vulnberability - how many on your network? Feb 13 2007 08:59PM
Gadi Evron (ge linuxbox org)
RE: Solaris telnet vulnberability - how many on your network? Feb 13 2007 09:46AM
Gadi Evron (ge linuxbox org) (2 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 13 2007 08:19PM
georg oppenberg deu mci com
Hi,

Solaris is now Open Source, so you can see yourself at
http://cvs.opensolaris.org/source/diff/onnv/onnv-gate/usr/src/cmd/cmd-in

et/usr.sbin/in.telnetd.c?r2=3629&r1=2923
what the problem and its resolution are.
There are also the blogs by Alan Hargreaves from SUN Australia at
http://blogs.sun.com/tpenta/entry/the_in_telnetd_vulnerability_exploit
and by Dan McDonald from SUN at
http://blogs.sun.com/danmcd/entry/how_opensolaris_did_its_job
describing how this vulnerability was first reported, fixed and alerts
and patches provided.

This is a big mistake but I see no reason to think of backdoors and
age-old problems on other OSes any longer. On the contrary I can see
the huge progress SUN has made and is making in regards to security and
openness.

Cheers
Georg Oppenberg

> On Mon, 12 Feb 2007, Oliver Friedrichs wrote:
> >
> > Am I missing something? This vulnerability is close to 10 years old.
> > It was in one of the first versions of Solaris after Sun moved off of
> > the SunOS BSD platform and over to SysV. It has specifically to do with
> > how arguments are processed via getopt() if I recall correctly.
>
> Hey Oliver! :)
>
> Well than, I guess it just became new again. And to be honest, I have to
> agree with a previous poster and suspect (only suspect) it could somehow
> be a backdoor rather than a bug.
>
> The reason why this vulnerability is so critical is the number of networks
> and organizations which rely on Solaris for critical production servers,
> as well as use telnet for internal communication on their LAN (now how
> smart is that? I'd rather use telnet on the Internet than on a local LAN).
>
> Further, there are quite a few third party appliances (some
> infrastructure back-end) that can not easily be patched running on
> Solaris (forget fuzzing or VA, people never even NMAP appliances they
buy).
>
> I am unsure of how long we will see this in to-do items of corporate
> security teams around the world, but I am sure Sun's /8 is getting a lot
> of action recently.
>
> >
> > Oliver
>
> Gadi.
>

[ reply ]
RE: Solaris telnet vulnberability - how many on your network? Feb 13 2007 07:36PM
Michal Zalewski (lcamtuf dione ids pl) (1 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 13 2007 09:01PM
Casper Dik Sun COM (2 replies)
Re[2]: Solaris telnet vulnberability - how many on your network? Feb 14 2007 12:32AM
Thierry Zoller (Thierry Zoller lu) (2 replies)
Re: Re[2]: Solaris telnet vulnberability - how many on your network? Feb 15 2007 06:49AM
Darren Reed (avalon caligula anu edu au) (2 replies)
Reflections on Trusting Trust [was: Re: Solaris telnet ...] Feb 16 2007 01:19AM
Gadi Evron (ge linuxbox org)
RE: Re[2]: Solaris telnet vulnberability - how many on your network? Feb 15 2007 07:10PM
Evans, Thomas (ttevans hawkcorp net)
RE: Re[2]: Solaris telnet vulnberability - how many on your network? Feb 14 2007 09:28PM
Roger A. Grimes (roger banneretcs com) (1 replies)
RE: Re[2]: Solaris telnet vulnberability - how many on your network? Feb 15 2007 12:55AM
Gadi Evron (ge linuxbox org)
Re: Solaris telnet vulnberability - how many on your network? Feb 13 2007 09:08PM
Gadi Evron (ge linuxbox org) (1 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 14 2007 09:15PM
Damien Miller (djm mindrot org) (1 replies)
Re: Solaris telnet vulnberability - how many on your network? Feb 15 2007 12:50AM
Gadi Evron (ge linuxbox org)


 

Privacy Statement
Copyright 2010, SecurityFocus