In association with heise online

16 February 2009, 14:41

Telnetd exploit on FreeBSD 7

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

A posting on the Full Disclosure mailing list has revealed what the FreeBSD Security team call a semi-remote root exploit for the telnetd service in FreeBSD 7, and later. By default, this service is disabled.

To exploit the vulnerability, a maliciously crafted library must be placed on the victim system beforehand, and then an attacker must connect via telnetd, passing the location of that library in the LD_PRELOAD environment variable. The malicious library is then loaded before the /bin/login process and executed as root.

Colin Percival, Security Officer for FreeBSD, recommends that FreeBSD 7.0-RELEASE, 7.1-RELEASE, 7-STABLE, and 8-CURRENT users ensure that telnetd is disabled. Dragonfly BSD is also reportedly vulnerable to the issue, but for a different reason, and patches for it, will not work on FreeBSD.

See also:

(djwm)

Print Version | Send by email | Permalink: http://h-online.com/-740131
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit