Re: Root exploit for FreeBSD

Previous thread: Re: LOR: vfs_subr.c ffs_softdep.c by Bas Smeelen on Friday, December 11, 2009 - 12:19 pm. (1 message)

Next thread: Re: Root exploit for FreeBSD by James Phillips on Friday, December 11, 2009 - 6:09 pm. (1 message)
From: Kevin Oberman
Date: Friday, December 11, 2009 - 4:23 pm

I'm sure that there are systems happily running MSDOS, but I bet not too
many are networked.

I know that there is still a lot of VMS out there and that it has
remained a cash cow for HP. It lived on primarily in the banking and
financial sector, though I guess the use is dropping since HP recently
outsourced support to India and that lead to the retirement of the last
of the original VMS developers, Andy Goldstein. 

Also, the the end of TECO as Andy was responsible for porting it to
almost every platform DEC ever sold (RSX, RSTS, VMS, TOPS-10 and
TOPS-20, RT-11, and several others) and continued to maintain it until
his retirement. (Most readers of this list probably don't even remember
TECO.)

And, for may years VMS had major network security problems, especially
the infamous default DECNET/DECNET account that lead to may compromises
and the second major network worm, Worms Against Nuclear Killers. (I
won't use the acronym so as not to offend our British readers. I found
out about that when the BBC interviewed me about it and I was told that
I could not utter the word.)
-- 
R. Kevin Oberman, Network Engineer
Energy Sciences Network (ESnet)
Ernest O. Lawrence Berkeley National Laboratory (Berkeley Lab)
E-mail: oberman@es.net			Phone: +1 510 486-8634
Key fingerprint:059B 2DDF 031C 9BA3 14A4  EADA 927D EBB3 987B 3751
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Ulf Zimmermann
Date: Friday, December 11, 2009 - 5:48 pm

Just go to Fry's Electronic. Most of their systems are still MS-Dos with

-- 
Regards, Ulf.

---------------------------------------------------------------------
Ulf Zimmermann, 1525 Pacific Ave., Alameda, CA-94501, #: 510-865-0204
You can find my resume at: http://www.Alameda.net/~ulf/resume.html
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Robert Huff
Date: Friday, December 11, 2009 - 9:59 pm

Ca _lot_ of small businesses have something similar.


					Robert Huff


_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?=
Date: Monday, December 14, 2009 - 4:07 am

That's a bet you're likely to lose - most of them are POS terminals,
industrial control applications etc.

DES
-- 
Dag-Erling Smørgrav - des@des.no
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Svein Skogen (Listmail Account)
Date: Monday, December 14, 2009 - 5:13 am

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Add to that the lot of them that are running IPX/SPX protocol... ;)

//Svein

- --
- --------+-------------------+-------------------------------
  /"\   |Svein Skogen       | svein@d80.iso100.no
  \ /   |Solberg Østli 9    | PGP Key:  0xE5E76831
   X    |2020 Skedsmokorset | svein@jernhuset.no
  / \   |Norway             | PGP Key:  0xCE96CE13
        |                   | svein@stillbilde.net
 ascii  |                   | PGP Key:  0x58CD33B6
 ribbon |System Admin       | svein-listmail@stillbilde.net
Campaign|stillbilde.net     | PGP Key:  0x22D494A4
        +-------------------+-------------------------------
        |msn messenger:     | Mobile Phone: +47 907 03 575
        |svein@jernhuset.no | RIPE handle:    SS16503-RIPE
- --------+-------------------+-------------------------------
         If you really are in a hurry, mail me at
               svein-mobile@stillbilde.net
 This mailbox goes directly to my cellphone and is checked
        even when I'm not in front of my computer.
- ------------------------------------------------------------
                     Picture Gallery:
          https://gallery.stillbilde.net/v/svein/
- ------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAksmK/gACgkQODUnwSLUlKSTbACgk63bpEw587FvI+sPpiC3BORP
GdoAnjT/o90mt0aNubLMsim9RfjIrtvR
=Rq2S
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?=
Date: Monday, December 14, 2009 - 6:03 am

Damn you, I was this >< close to successfully repressing that memory!

DES
-- 
Dag-Erling Smørgrav - des@des.no
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Borja Marcos
Date: Monday, December 14, 2009 - 8:15 am

I was avoiding to jump into this, but... Maybe this hilarious proposal will cure your pain, dude.

http://ietfdocs.potaroo.net/rfc/rfc1791.txt

I remember that around the early 90's  I read one of those peecee magazine authors (maybe Jerry Pournelle) asking the IETF to, please, drop that TCP/IP thingy and instead choose a standard, widely used protocol for the Internet: IPX.

Let me touch more bad neurons for you: X.400 :)






Borja.

_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?=
Date: Monday, December 14, 2009 - 8:53 am

Umm, is IPX even routable?

Note that we still have IPX/SPX and NCP support in the kernel...

options         IPX                     #IPX/SPX communications protocols
options         NCP                     #NetWare Core protocol

DES
-- 
Dag-Erling Smørgrav - des@des.no
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Wes Peters
Date: Monday, December 14, 2009 - 8:32 pm

Yup, it sure is.  Xylan had IPX routing in their switch/routers when I
worked there, done by the same group that did IP routing.  It was
bugly.


-- 
Against stupidity the very gods Themselves contend in vain.
                                         Friedrich Schiller
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Svein Skogen (Listmail Account)
Date: Tuesday, December 15, 2009 - 3:35 am

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


	I cleared out some recipient adresses before answering this...

So does the higher featuresets of IOS (Cisco). I've actually done a fair
bit of that sort of routing (IPX, DECnet, and whatnot) for a living
"back then" before my health gave up on me (landing me on disability
pension).

As a matter of fact, you could even route NETBEUI if you encapsulated it
in something else (and thus i reality bridged it). We did that for a few
customers, over frame-relay, as late as 2001 (when I moved on to a
different part of the company).

Basically, any signal that you can connect to an interface on a router,
CAN be routed, provided your NOC team is creative enough.

//Svein

- --
- --------+-------------------+-------------------------------
  /"\   |Svein Skogen       | svein@d80.iso100.no
  \ /   |Solberg Østli 9    | PGP Key:  0xE5E76831
   X    |2020 Skedsmokorset | svein@jernhuset.no
  / \   |Norway             | PGP Key:  0xCE96CE13
        |                   | svein@stillbilde.net
 ascii  |                   | PGP Key:  0x58CD33B6
 ribbon |System Admin       | svein-listmail@stillbilde.net
Campaign|stillbilde.net     | PGP Key:  0x22D494A4
        +-------------------+-------------------------------
        |msn messenger:     | Mobile Phone: +47 907 03 575
        |svein@jernhuset.no | RIPE handle:    SS16503-RIPE
- --------+-------------------+-------------------------------
         If you really are in a hurry, mail me at
               svein-mobile@stillbilde.net
 This mailbox goes directly to my cellphone and is checked
        even when I'm not in front of my computer.
- ------------------------------------------------------------
                     Picture Gallery:
          https://gallery.stillbilde.net/v/svein/
- ------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (MingW32)
Comment: Using GnuPG with Mozilla - ...
From: Rink Springer
Date: Tuesday, December 15, 2009 - 1:06 am

3Com CoreBuilder's (at least the 3500 model) were also capable of fully
routing IPX. Never tried it though, as IPX was obsoleted by that time
anyway :-)

-- 
Rink P.W. Springer                                - http://rink.nu
"Beauty often seduces us on the road to truth."
- Dr. Wilson
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Pierre Beyssac
Date: Tuesday, December 15, 2009 - 7:02 am

Hello,

Since upgrading my world with a -current built last night, cvsup
dumps core on me. Any idea?

It is a Intel/ATOM 330 box used in 64bit mode. Everything else on
the box runs fixe.

Recompiling cvsup + ezm3 didn't fix the problem; neither did trying
a libc from October.

% cvsup  -gs standard-supfile
Connected to cvsup3.fr.FreeBSD.org
Updating collection src-all/cvs
 Edit src/sbin/ipfw/ipfw.8
zsh: illegal hardware instruction (core dumped)  cvsup -gs standard-supfile

% gdb cvsup cvsup.core
GNU gdb 6.1.1 [FreeBSD]
Copyright 2004 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB.  Type "show warranty" for details.
This GDB was configured as "amd64-marcel-freebsd"...(no debugging symbols found)...
Core was generated by `cvsup'.
Program terminated with signal 4, Illegal instruction.
Reading symbols from /lib/libz.so.5...(no debugging symbols found)...done.
Loaded symbols for /lib/libz.so.5
Reading symbols from /lib/libm.so.5...(no debugging symbols found)...done.
Loaded symbols for /lib/libm.so.5
Reading symbols from /lib/libc.so.7...(no debugging symbols found)...done.
Loaded symbols for /lib/libc.so.7
Reading symbols from /libexec/ld-elf.so.1...(no debugging symbols found)...done.
Loaded symbols for /libexec/ld-elf.so.1
#0  0x00000008009ffe2b in gmtime_r () from /lib/libc.so.7
(gdb) where
#0  0x00000008009ffe2b in gmtime_r () from /lib/libc.so.7
#1  0x00000008009ff8be in gmtime_r () from /lib/libc.so.7
#2  0x0000000800a00596 in gmtime_r () from /lib/libc.so.7
#3  0x0000000800a007a8 in gmtime_r () from /lib/libc.so.7
#4  0x0000000800a03b98 in time () from /lib/libc.so.7
#5  0x00000008009ff53f in timeoff () from /lib/libc.so.7
#6  0x0000000800a00e17 in gmtime () from /lib/libc.so.7
#7  0x00000000004a643a in calloc ()
#8  0x000000000043aec7 in ?? ...
From: Gary Jennejohn
Date: Tuesday, December 15, 2009 - 9:49 am

On Tue, 15 Dec 2009 15:02:34 +0100

I reported this everal weeks ago but there was never a satisfactory
resolution to the problem.

One poster (scf@) reported that using a 32-bit binary solves the problem.

In my experience running cvsup against a remote server (to keep a local
CVS tree up to date) works just fine.

Are you also running cvsupd and attaching to it?

I've found that not starting cvsupd in /etc/rc.conf and instead starting
it without -C in a shell script just before invoking cvsup works, so
I use something like this:

/usr/local/sbin/cvsupd&
sleep 1
/usr/local/bin/cvsup supfile

and have localhost in supfile.

Otherwise I suggest using csup, which does not exhibit any bugs.

---
Gary Jennejohn
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Gary Jennejohn
Date: Tuesday, December 15, 2009 - 10:03 am

On Tue, 15 Dec 2009 17:49:05 +0100

One very important thing which I forgot to mention was that removing
/usr/share/zoneinfo/UTC seems to allow cvsup to run to completion.

---
Gary Jennejohn
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Pierre Beyssac
Date: Tuesday, December 15, 2009 - 10:21 am

Me too! So weird (even though my machine is configured with CET).
So the problem definitely seems to be time-related...
-- 
Pierre Beyssac	      	    		pb@fasterix.frmug.org
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Pierre Beyssac
Date: Tuesday, December 15, 2009 - 10:19 am

Yes, I did that too, a 32bit cvsup binary I copied from another

No. I don't have a local server, cvsup is running against a remote
server.

More info:

When running from gdb, the error shows up as SIGSEGV on a callq to
an invalid address. Could this be a dynamic link error?

Here's a disassembly of the code; actually it seems to be somewhere
inside lib/libc/stdtime/localtime:timesub() (called by gmtime_r).

Program received signal SIGSEGV, Segmentation fault.
0x00000008009ffe2b in gmtime_r () from /lib/libc.so.7

0x00000008009ffe0b <gmtime_r+2171>:     mov    1364798(%rip),%r14        # 0x800b4d150 <__thr_jtable+90512>
0x00000008009ffe12 <gmtime_r+2178>:     mov    %edx,%r13d
0x00000008009ffe15 <gmtime_r+2181>:     mov    (%r14),%rax
0x00000008009ffe18 <gmtime_r+2184>:     mov    %rax,0xee68(%rsp)
0x00000008009ffe20 <gmtime_r+2192>:     xor    %eax,%eax
0x00000008009ffe22 <gmtime_r+2194>:     test   %rdi,%rdi
0x00000008009ffe25 <gmtime_r+2197>:     je     0x8009fff80 <gmtime_r+2544>
0x00000008009ffe2b <gmtime_r+2203>:     callq  0x80095b4cc <signgam+181968>
0x00000008009ffe30 <gmtime_r+2208>:     test   %eax,%eax
0x00000008009ffe32 <gmtime_r+2210>:     jne    0x8009fff52 <gmtime_r+2498>

(gdb) print signgam 

True, I just did that following a private suggestion and it works just fine :-)
-- 
Pierre Beyssac	      	    		pb@fasterix.frmug.org
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
From: Daniel O'Connor
Date: Tuesday, December 15, 2009 - 7:30 pm

<snip>

Please don't thread hijack, it breaks the flow of conversation and is 
annoying.

ie don't just pick some random message and hit reply then change the 
subject etc.. Your mail client adds headers which cause it to appear as 
part of the original thread even though the subject has changed (this 
is a feature)

-- 
Daniel O'Connor software and network engineer
for Genesis Software - http://www.gsoft.com.au
"The nice thing about standards is that there
are so many of them to choose from."
  -- Andrew Tanenbaum
GPG Fingerprint - 5596 B766 97C0 0E94 4347 295E E593 DC20 7B3F CE8C
Previous thread: Re: LOR: vfs_subr.c ffs_softdep.c by Bas Smeelen on Friday, December 11, 2009 - 12:19 pm. (1 message)

Next thread: Re: Root exploit for FreeBSD by James Phillips on Friday, December 11, 2009 - 6:09 pm. (1 message)