home page

copyright 1999/2005 vrl labs. - tutti i diritti riservati

home
advisories
library
links
news
review
servizi
tools
freaknet.org
dyne.org
your account

 
 

.:::.search.:::.



 

.:::.who's online.:::.

There are currently, 1 guest(s) and 0 member(s) that are online.

..::lastest advisories::..


Lynx Command Line URL CRLF Injection Vulnerability

Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability

FreeBSD Ptrace/SPIgot Insufficient Signal Verification Denial of Service Vulnerability

Dotless IP Addresses Can Cause IE to Move into Intranet Zone

Invalid RDP Data can Cause Terminal Service Failure

phpBB Allows Remote Users to Modify Default SQL Queries

CDP Vulnerability in Cisco Routers

Hi-Resolution System`s MacAdministrator Hidden Files Disclosure and Access Vulnerability

TYPSoft FTP Server STOR/RETR Denial of Service Vulnerability

Security Bug Found in ht://Dig htsearch CGI (DoS, File Exposure)

Account Management Vulnerabilities in Ipswitch IMail Server

Cisco PIX Firewall Manager Password Disclosure Vulnerability

Atomz Search Engine Cross-site Scripting Vulnerability

Security Bug Found in PostNuke (and possibly PHPNuke

Additional Details Released on the Zone Spoofing Vulnerability

Ipswitch Web Calendaring Buffer Overflow
all advisories


..:::..lastest files..:::..


DNS Flood Detector v1.0

wormulon v0.1.3

ulogd-php v0.7

FWReport v1.1.5

Netl, a Customizable Low Level Network Monitor

WinDefender 2.1.6

NTDaddy, ASP Based Administration Kit

Virge v2.07

PCX Firewall v2.7

Port Scan Attack Detector (psad) v0.9.2

NARC v0.5.1

Nimda Notifyer v1.2

IIS Worms Detector v1.1

Legion of the Bouncy Castle Java Cryptography API v1.09

Samhain 1.2.8
all files








Hi-Resolution System`s MacAdministrator Hidden Files Disclosure and Access Vulnerability
posted by: valvoline on 20/10/2001 @ 10.06.20
Summary:
MacAdministrator is a powerful management tool for computers running MacOS. It provides an extensive range of features, under administrator control, for large and small networks independent of server type.


Vulnerable systems:
MacAdministrator version 1.7
MacAdministrator version 2.0.4fc4

MacAdministrator allows using of the hidden file attribute on the HFS catalog system thus providing a way of maintaining and administrating a network of multiple users. It also provides the administrator with an override account on each node connected to MacAdministrator`s virtual network. Further, MacAdministrator secures the Navigation services (the Standard File Manager APIs) in the MacOS development toolbox, from accessing certain features (e.g. making sure hidden files do not show up and allowing access locking).

The problem comes in however, when certain programs are linked at compile time against the old version of the Macintosh toolkit or other custom crafted routines. This causes them to ignore the hidden file flags, which in turn leads to the disclosure of hidden files.

This in itself provides a problem, as users could venture into hidden folders and expose hidden filenames, possibly sensitive information that could compromise the privacy of other users or the system. Furthermore, users are also able to access and even open/read such unprotected hidden files on the system, increasing the likelihood of the user to view private information and sensitive system information.

Indeed this is what can be achieved with MacAdministrator`s preference files, resident on every computer node in its virtual network (distribution design feature). The file would allow a malicious user the possibility to disclose settings and manipulate vital configurations settings of the MacAdministrator system (as files do not appear to be read-only), and even gain access to the override account name and encrypted password (which would effectively compromise all override accounts on the connected nodes if the user in turn compromised the password).

Part of the problem is that MacAdministrator relies on using hidden files to try securing a few sensitive/private files such as original extensions, control panels, preferences, and the user folders of other users (user folders are however also coupled with access locking preventing exposure of docs, but does give indication of what login names are available).


Exploit:
Proof of concept can be presented by compiling the example program "HexDump" (user account required) provided by the Think Pascal 4.0 program package and then using it to browse through the file system hierarchy. Because Think Pascal provides its own runtime library with custom routines and toolbox (released from some OLD MacOS release) it neglects to handle hidden files properly.


Suggested solution:
The long and strenuous solution is for Hi-Resolution Systems to make MacAdministrator secure system routines by restriction of some sort and mandatory locking of configuration files (administrators do not appear to be able to do so by configuration currently).

Current administrators are advised to tighten configurations a lot more by allowing a certain set of applications execution privileges only so rogue programs cannot be run which may pose a security risk and perhaps update older applications in favor of newer releases that have been compiled against a newer Mac Toolbox. Hiding files should also not be relied on for protecting sensitive information.


Additional information
The information has been provided by MD5(mithrandir@geek.com)
comments: (0) |  send this story to a friendprint a friendly page

.:::.mailing list.:::.


subscribe
unsubscribe

 
 

.:::.Login.:::.

Nickname

Password



Don't have an account yet? You can create one. As registered user you have some advantages like, comments configuration and post comments with your name.
 

..:::..news..:::..


Scans to expose Windows RPC vulnerability are increasing

Update Windows before it gets Blasted

Blaster rewrites Windows worm rules

Microsoft to hackers: Don`t publish code

Senator Backs Off Backdoors

SafeWeb ain`t all that

Hackers launch `cyber jihad` on US

Net security: An oxymoron

Microsoft Patch Yanked

Security Attacks Set to Double in 2001

`Govnet` Would Be Costly, Prone to Failure-Experts

Microsoft to Prioritize Security Bugs

XP a National Security Threat?

`Smart Card` Technology Gets Second Look

U.S. could close Gates on hackers, terrorists

Encryption: How Prevalent Is It?

bv-Control for Microsoft SQL Server Launched

The Achilles` Heel of Remote Net Mgmt

Former Federal Agent Calls Xp a Threat to National Security

`Net Routers Still Feeling Effects of Code Red, Nimda

RIAA Attempts to Influence Anti-Terrorism Bill

FBI shuts down `IRA` website

$200m WinXP media assault begins

Symantec users risk redirection to hacker sites

Anthrax-laced letter to MS license div suspected

Internet Security Revenue To Exceed $14 Billion by 2005
all news


..:::..lastest docs..:::..


Ethernet Games Sources

Ethernet Games Slides

EthernetGames DOCS

CryptoWorkshop Sources

CryptoWorkshop DOCS

CryptoWorkshop Slides

An Overview of LIDS

How to tell if your Linux box has been cracked

CRYPTO-GRAM - October 15 2001

Netfilter and iptables: Stateful firewalling for Linux

Comparing E-mail Server Virus Protection Solutions

Cryptography General Discussions and Implementations

THINKERS ANONYMOUS

The world will end tomorrow - official

Kerberos and Windows 2000
all docs


..:::..lastest reviews..:::..


NSA Security-enhanced Linux v2003081307

Sophos Delivers MailMonitor For Notes/Domino

Evidian Announces NetWall 6

DbEncrypt Flexible

LANGuard S.E.L.M.

BlackICE Defender

ftp-voyager 8.0.0.3 - Wins Again!

sygate personal firewall 4.2

FreeBSD 4.4 Released

LSM-based Security-Enhanced Linux
all reviews

.:::. webdesign & webprogramming: valv`0 (PGP KEY) .:::. co-ordinators: hellbreak (PGP KEY) & cmcsynth (PGP KEY) .:::.

All logos and trademarks in this site are property of their respective owner, all the rest © 2001/2219 VRL Team
site powered by: ALIP site creator v1.0b © 2001/2219 VRL Team