Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 24 Jan 1999 11:14:19 -0500 (EST)
From:      Robert Watson <robert@cyrus.watson.org>
To:        cjclark@home.com
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: bin Directory Ownership
Message-ID:  <Pine.BSF.3.96.990123211848.3494B-100000@fledge.watson.org>
In-Reply-To: <199901231551.KAA05725@cc942873-a.ewndsr1.nj.home.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sat, 23 Jan 1999, Crist J. Clark wrote:

> Robert Watson wrote,
> > Access to the bin account is very limited;
> > effectively, to acquire a uid bin process capable of modifying the
> > binaries, you would first have to have a uid root process that you had
> > subverted.
> 
> I realize that, but the argument goes that if someone /did/ access
> root, he could give himself long-term access to bin and possibly other
> administrative users. Since the actions of these other administrative
> users are not as tightly watched as root (e.g. no syslog message when
> you su to one), it might be possible to maintain access for a long
> time (even if the original way he accessed root had been closed).

Come now--if I had root access on machine and really didn't like you, I'd
install my spiffy stealth kernel module that hides its presence from
modstat etc (actualy, this is still an lkm so might not work on 3.*),
accepts commands to run as root via the payload of ICMP ping packages. :)
I think this argument might apply to only the weakest of script kiddies;
besides which, FreeBSD emails you about changes to the password file each
night; if they're stupid enough to leave backdoors in your password file,
they're stupid enough to not interfere with the security script. :)  If
they're not that stupid and you're not using securelevels, the you
probably ought to reinstall anyway, as there are many many ways to trojan
a machine; assuming you can catch all of them by simple inspection might
not be wise.

> BTW, I am running a 2.2.*, 2.2.7.

I believe that in 3.x many of the files owned by bin are now owned by
root.

  Robert N Watson 

robert@fledge.watson.org              http://www.watson.org/~robert/
PGP key fingerprint: 03 01 DD 8E 15 67 48 73  25 6D 10 FC EC 68 C1 1C

Carnegie Mellon University            http://www.cmu.edu/
TIS Labs at Network Associates, Inc.  http://www.tis.com/
SafePort Network Services             http://www.safeport.com/



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.96.990123211848.3494B-100000>