|
From: Wall, Kevin <Kevin.Wall@qwest.com>
Date: Fri Jul 09 2004 - 13:30:59 EDT
Matthias Benkmann wrote...
> I can't say I've looked at much exploit-code so far but the POC exploits
No; sometimes they use other shells, such as /bin/bash, /bin/ash,
Also, presumably, you'd still have to set SHELL env variable, so
Worst of all, you now have yourself a maintenance nightmare. Think
#!/bin/sh
to whatever full path name you've switched the shell to. And you'd have
Yuck! No thanks!
> I'm aware that a dedicated attacker who targets my box specifically will
Well, it probably would stop the script kiddies--for awhile at least.
Also, if you keep on top of patches, have appropriate firewall rules
> If renaming the shell is not enough, how about renaming all of the
Man, that would REALLY become a maintenance nightmare. You'd have to
---
-kevin wall
Qwest IT - Application Security Team
"The reason you have people breaking into your software all
over the place is because your software sucks..."
-- Former whitehouse cybersecurity advisor, Richard Clarke,
at eWeek Security Summit
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Fri Jul 09 14:45:07 2004
This archive was generated by hypermail 2.1.8 : Fri Jul 09 2004 - 15:02:52 EDT |
Custom Search
|