вопросы безопасности

Ответить
 • Просмотры: 2
Аватара пользователя
mar

вопросы безопасности

Сообщение mar »

Обнаружена уязвимость в FreeBSD 5.1 execve(). Локальный атакующий может вызвать отказ в обслуживании системы. Подробности c
SecurityLab
Аватара пользователя
Guest

Re: вопросы безопасности

Сообщение Guest »

А там всё на английском. Простому русскому человеку как понять? Ведь тема достаточно интересная...
Аватара пользователя
Demiurg

Re: вопросы безопасности

Сообщение Demiurg »

...а как лучше (ради стабильности системы), обновлять только ядро или и все системные библиотеки и программы... что лучше (самое необходимое) поместить в /usr/src чтобы после апдейтов проблем поменьше возникало?..
Аватара пользователя
mar

Re: вопросы безопасности

Сообщение mar »

к предыдущей заметке (уязвимость в FreeBSD 5.1 execve().)

Уязвимы системы:

FreeBSD 5.1-RELEASE/Alpha. Возможно другие версии

FreeBSD 5.1-RELEASE/IA32 не уязвима.

Насчет других архитектур - неизвестно, но возможна уязвимость.

Риск: низкий

Уязвимость локальная

дата: 23 июня 2004

описание:

Возможна атака на ядро FreeBSD/Alpha при специальном обращении к системному вызову execve().

Приведен разбор кодов и заплатка

продолжим Изображение

2004-06-30 В коде ядра выявлена
уязвимость в совместимости с Linux-приложениями
(Linux binary compatibility mode input validation error), затрагивающая все версии 4.x и 5.x *:

Во FreeBSD, как известно, обеспечивается совместимость с бинарным кодом Linux при помощи подгружаемых модулей.

Выявленна ошибка получения некоторых системных вызовов Linux, что может привести к получению доступа к памяти без достаточной валидации.

При локальной атаке возможно чтение и/или перезапись участков памяти ядра (portions of kernel memory), *что может привести выявлению значимой информации, или к потенциальной возможности повышения привелегий. Локальная атака может вызвать сбой в системе (system panic).

Как с этим бороться:

1) внимательно прочесть документацию (ссылка дана наверху)

2) до обновления можно запретть совместимость с Linux-приложениями, выгрузив соответствующий модуль

3) обновить систему до сегодняшних 4-STABLE; или *RELENG_5_2,

RELENG_4_10, RELENG_4_9, или RELENG_4_8 security branch

4) или, как вариант - пропатчить систему:

a) скачать заплатку по одной из приведенных ссылок и проверить PGP-подпись



Код:

Код: Выделить всё

 
[FreeBSD 5.2] 
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CE...3/linux5.patch 
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CE...nux5.patch.asc 
[FreeBSD 4.8, 4.9, 4.10] 
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CE...3/linux4.patch 
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CE...nux4.patch.asc

b) поставить заплатку:

# cd /usr/src

# patch < /path/to/patch

с) перекомпилировать ядро и перезагрузить систему



NB!!! рекомендуется внимательно ознакомится с версиями и именами заменяемых исходных файлов, а также с PGP-подписью (все данные - все по той же ссылке)





[s]Исправлено: mar, 12:16 3-07-2004[/s]





[s]Исправлено: mar, 12:20 3-07-2004[/s]
Аватара пользователя
Belansky

Re: вопросы безопасности

Сообщение Belansky »

И снова
патч
по безопасности. При генерации списка сетевых интерфейсов ядро пишет в часть буфера, не обнуляя ее. В результате предыдущее содержимое буфера может быть доступно процессу. Процесс пользователя может получить доступ к 12 байтам данных. Эта память может содержать такую информацию, как части кэша файла или буфера терминала (например, в буфере терминала может находится пароль пользователя).
Аватара пользователя
SantaXP

Re: вопросы безопасности

Сообщение SantaXP »

Хм... Слушайте, раз уж тема так называется - мне очень не хочется, чтобы мою систему кто-нить хакнул, поэтому - подскажите какую прогу, с помощью которой можно было бы искать руткиты и т.д. То есть, чтобы она как ipfw работала на фоне и не давала никому взломать мою Фри. Изображение
Аватара пользователя
SantaXP

Re: вопросы безопасности

Сообщение SantaXP »

Belansky

А эти патчи, они устанавливаются каждый по отдельности или последующий содержит все остальные изменения в системе из предыдущих???

И ещё - их инсталить обязательно? Насколько их неналичие на компе может отразиться на безопастности системы???
Аватара пользователя
Belansky

Re: вопросы безопасности

Сообщение Belansky »

Очередное обновление по безопасности.


Цитата:



FreeBSD-SA-05:21.openssl Security Advisory

The FreeBSD Project



Topic: Potential SSL 2.0 rollback



Category: contrib

Module: openssl

Announced: 2005-10-11

Credits: Yutaka Oiwa

Affects: All FreeBSD releases.

Corrected: 2005-10-11 11:52:46 UTC (RELENG_6, 6.0-STABLE)

2005-10-11 11:53:03 UTC (RELENG_6_0, 6.0-RELEASE)

2005-10-11 11:52:01 UTC (RELENG_5, 5.4-STABLE)

2005-10-11 11:52:28 UTC (RELENG_5_4, 5.4-RELEASE-p8)

2005-10-11 11:52:13 UTC (RELENG_5_3, 5.3-RELEASE-p23)

2005-10-11 11:50:50 UTC (RELENG_4, 4.11-STABLE)

2005-10-11 11:51:45 UTC (RELENG_4_11, 4.11-RELEASE-p13)

2005-10-11 11:51:20 UTC (RELENG_4_10, 4.10-RELEASE-p19)

CVE Name: CAN-2005-2969



For general information regarding FreeBSD Security Advisories,

including descriptions of the fields above, security branches, and the

following sections, please visit

.



I. Background



The OpenSSL library implements the Secure Sockets Layer and Transport

Layer Security protocols, as well as providing a large number of basic

cryptographic functions.



The Secure Sockets Layer protocol exists in two versions and includes a

mechanism for negotiating the protocol version to be used. If the

protocol is executed correctly, it is impossible for a client and

server both capable of the newer version of the protocol (SSLv3) to end

up using the older version of the protocol (SSLv2).



II. Problem Description



In order to provide bug-for-bug compatibility with Microsoft Internet

Explorer 3.02, a verification step required by the Secure Sockets Layer

protocol can be disabled by using the SSL_OP_MSIE_SSLV2_RSA_PADDING

option in OpenSSL. This option is implied by the frequently-used

SSL_OP_ALL option.



III. Impact



If the SSL_OP_MSIE_SSLV2_RSA_PADDING option is enabled in a server

application using OpenSSL, an attacker who is able to intercept and

tamper with packets transmitted between a client and the server can

cause the protocol version negotiation to result in SSLv2 being used

even when both the client and the server support SSLv3. Due to a

number of weaknesses in the SSLv2 protocol, this may allow the attacker

to read or tamper with the encrypted data being sent.



Applications which do not support SSLv2, have been configured to not

permit the use of SSLv2, or do not use the SSL_OP_MSIE_SSLV2_RSA_PADDING

or SSL_OP_ALL options are not affected.



IV. Workaround



No workaround is available.



V. Solution



NOTE WELL: The solution described below causes OpenSSL to ignore the

SSL_OP_MSIE_SSLV2_RSA_PADDING option and hence to require conformance

with the Secure Sockets Layer protocol. As a result, this solution

will reintroduce incompatibility with Microsoft Internet Explorer 3.02

and any other applications which exhibit the same protocol violation.



Perform one of the following:



1) Upgrade your vulnerable system to 4-STABLE or 5-STABLE, or to the

RELENG_5_4, RELENG_5_3, RELENG_4_11, or RELENG_4_10 security branch

dated after the correction date.



2) To patch your present system:



The following patches have been verified to apply to FreeBSD 4.10,

4.11, 5.3, and 5.4 systems.



a) Download the relevant patch from the location below, and verify the

detached PGP signature using your PGP utility.



# fetch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CE.../openssl.patch


# fetch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CE...nssl.patch.asc




b) Execute the following commands as root:



# cd /usr/src

# patch < /path/to/patch



c) Recompile the operating system as described in

.



Note that any statically linked applications that are not part of the

base system (i.e. from the Ports Collection or other 3rd-party sources)

must be recompiled.



All affected applications must be restarted for them to use the

corrected library. Though not required, rebooting may be the easiest

way to accomplish this.



VI. Correction details



The following list contains the revision numbers of each file that was

corrected in FreeBSD.



Branch Revision

Path

- -------------------------------------------------------------------------

RELENG_4

src/crypto/openssl/crypto/opensslv.h 1.1.1.1.2.11

src/crypto/openssl/ssl/s23_srvr.c 1.2.2.6

RELENG_4_11

src/UPDATING 1.73.2.91.2.14

src/sys/conf/newvers.sh 1.44.2.39.2.17

src/crypto/openssl/crypto/opensslv.h 1.1.1.1.2.10.4.1

src/crypto/openssl/ssl/s23_srvr.c 1.2.2.5.8.1

RELENG_4_10

src/UPDATING 1.73.2.90.2.20

src/sys/conf/newvers.sh 1.44.2.34.2.21

src/crypto/openssl/crypto/opensslv.h 1.1.1.1.2.10.2.1

src/crypto/openssl/ssl/s23_srvr.c 1.2.2.5.6.1

RELENG_5

src/crypto/openssl/crypto/opensslv.h 1.1.1.1.15.2.2

src/crypto/openssl/ssl/s23_srvr.c 1.7.6.1

RELENG_5_4

src/UPDATING 1.342.2.24.2.17

src/sys/conf/newvers.sh 1.62.2.18.2.13

src/crypto/openssl/crypto/opensslv.h 1.1.1.15.2.1.2.1

src/crypto/openssl/ssl/s23_srvr.c 1.7.10.1

RELENG_5_3

src/UPDATING 1.342.2.13.2.26

src/sys/conf/newvers.sh 1.62.2.15.2.28

src/crypto/openssl/crypto/opensslv.h 1.1.1.15.4.1

src/crypto/openssl/ssl/s23_srvr.c 1.7.8.1

RELENG_6

src/crypto/openssl/ssl/s23_srvr.c 1.7.12.1

src/crypto/openssl/crypto/opensslv.h 1.1.1.16.2.1

RELENG_6_0

src/UPDATING 1.416.2.3.2.1

src/crypto/openssl/crypto/opensslv.h 1.1.1.16.4.1

src/crypto/openssl/ssl/s23_srvr.c 1.7.14.1
Аватара пользователя
Belansky

Re: вопросы безопасности

Сообщение Belansky »

Очередное обновление по безопасности. Затрагивает пятую ветку.


Цитата:



FreeBSD-SA-06:08.sack Security Advisory

The FreeBSD Project



Topic: Infinite loop in SACK handling



Category: core

Module: netinet

Announced: 2006-02-01

Credits: Scott Wood

Affects: FreeBSD 5.3 and 5.4

Corrected: 2006-01-24 01:16:18 UTC (RELENG_5, 5.4-STABLE)

2006-02-01 19:43:10 UTC (RELENG_5_4, 5.4-RELEASE-p11)

2006-02-01 19:43:36 UTC (RELENG_5_3, 5.3-RELEASE-p26)

CVE Name: CVE-2006-0433



For general information regarding FreeBSD Security Advisories,

including descriptions of the fields above, security branches, and the

following sections, please visit

.



I. Background



SACK (Selective Acknowledgement) is an extension to the TCP/IP protocol

that allows hosts to acknowledge the receipt of some, but not all, of

the packets sent, thereby reducing the cost of retransmissions.



II. Problem Description



When insufficient memory is available to handle an incoming selective

acknowledgement, the TCP/IP stack may enter an infinite loop.



III. Impact



By opening a TCP connection and sending a carefully crafted series of

packets, an attacker may be able to cause a denial of service.



IV. Workaround



On FreeBSD 5.4, the net.inet.tcp.sack.enable sysctl can be used to

disable the use of SACK:



# sysctl net.inet.tcp.sack.enable=0



No workaround is available for FreeBSD 5.3.



V. Solution



Perform one of the following:



1) Upgrade your vulnerable system to 5-STABLE or to the RELENG_5_4 or

RELENG_5_3 security branch dated after the correction date.



2) To patch your present system:



The following patch have been verified to apply to FreeBSD 5.3 and

5.4 systems.



a) Download the relevant patch from the location below, and verify the

detached PGP signature using your PGP utility.



# fetch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CE...:08/sack.patch


# fetch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CE...sack.patch.asc




b) Apply the patch.



# cd /usr/src

# patch < /path/to/patch



c) Recompile your kernel as described in

and reboot the

system.



VI. Correction details



The following list contains the revision numbers of each file that was

corrected in FreeBSD.



Branch Revision

Path

- -------------------------------------------------------------------------

RELENG_5

src/sys/netinet/tcp_sack.c 1.3.2.10

RELENG_5_4

src/UPDATING 1.342.2.24.2.20

src/sys/conf/newvers.sh 1.62.2.18.2.16

src/sys/netinet/tcp_sack.c 1.3.2.5.2.1

RELENG_5_3

src/UPDATING 1.342.2.13.2.29

src/sys/conf/newvers.sh 1.62.2.15.2.31

src/sys/netinet/tcp_sack.c 1.3.4.1
Аватара пользователя
Belansky

Re: вопросы безопасности

Сообщение Belansky »

Очередное обновление по безопасности.

FreeBSD-SA-07:01.jail
Ответить

Вернуться в «Общий по FreeBSD»