<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in This Old Vulnerability: An AIX FTP client retrospective</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Thu, 09 Jul 2009 01:26:56 -0000</lastBuildDate><item><title>Re: This Old Vulnerability: An AIX FTP client retrospective</title><link>http://www.matasano.com/log/923/this-old-vulnerability-an-aix-ftp-client-retrospective/#comment-12365781</link><description>I really like reading in this site.. I always learn a lot from you Dave.. Keep it up!!!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">movingketz002</dc:creator><pubDate>Thu, 09 Jul 2009 01:26:56 -0000</pubDate></item><item><title>Re: This Old Vulnerability: An AIX FTP client retrospective</title><link>http://www.matasano.com/log/923/this-old-vulnerability-an-aix-ftp-client-retrospective/#comment-2322993</link><description>They did it again:&lt;br&gt;&lt;br&gt;&lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=616" rel="nofollow"&gt;http://labs.idefense.com/intelligence/vulnerabi...&lt;/a&gt;&lt;br&gt;&lt;br&gt;Only this time with strcpy</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">forever.b0rked</dc:creator><pubDate>Tue, 30 Oct 2007 16:23:23 -0000</pubDate></item><item><title>Re: This Old Vulnerability: An AIX FTP client retrospective</title><link>http://www.matasano.com/log/923/this-old-vulnerability-an-aix-ftp-client-retrospective/#comment-2322990</link><description>Roden:&lt;br&gt;&lt;br&gt;The !/bin/sh issue I am referring to is a vulnerability I think I remember from the distant past.  I mention that right above the listing of that set of vulnerabilities.  If it did exist, it would have been fixed 10+ years ago.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave G.</dc:creator><pubDate>Fri, 17 Aug 2007 10:33:32 -0000</pubDate></item><item><title>Re: This Old Vulnerability: An AIX FTP client retrospective</title><link>http://www.matasano.com/log/923/this-old-vulnerability-an-aix-ftp-client-retrospective/#comment-2322992</link><description>Sorry for my hasty spelling in the previous comment.&lt;br&gt;&lt;br&gt;If the ftp program is used as a non-root user in AIX 5L 5.3, then the !/bin/sh only gives a shell prompt for the non-root user.&lt;br&gt;&lt;br&gt;# su - guest&lt;br&gt;$ ftp&lt;br&gt;ftp&amp;gt; !/bin/sh&lt;br&gt;$ id&lt;br&gt;uid=100(guest) gid=100(usr)&lt;br&gt;&lt;br&gt;&lt;br&gt;The problem is not so simple, but the security flaw exists.&lt;br&gt;&lt;br&gt;&lt;a href="https://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;amp;heading=AIX53&amp;amp;path=%252F200707%252FSECURITY%252F20070726%252Fdatafile095634&amp;amp;label=UPDATE-AIX+ftp+gets%2528%2529+Buffer+Overflow+Vulnerabilities" rel="nofollow"&gt;https://www14.software.ibm.com/webapp/set2/subs...&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;IBM provides the following fixes:&lt;br&gt;&lt;br&gt;        AIX Level           APAR number       Availability&lt;br&gt;        --------------------------------------------------------------------&lt;br&gt;        5.2.0               IZ01812           10/31/2007 (subject to change)&lt;br&gt;        5.3.0               IZ01813           11/27/2007 (subject to change)&lt;br&gt;&lt;br&gt;        AIX Version 5 APARs can be downloaded from:&lt;br&gt;&lt;br&gt;        &lt;a href="http://www.ibm.com/servers/eserver/support/unixservers/aixfixes.html" rel="nofollow"&gt;http://www.ibm.com/servers/eserver/support/unix...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Roden</dc:creator><pubDate>Fri, 17 Aug 2007 06:31:12 -0000</pubDate></item><item><title>Re: This Old Vulnerability: An AIX FTP client retrospective</title><link>http://www.matasano.com/log/923/this-old-vulnerability-an-aix-ftp-client-retrospective/#comment-2322991</link><description>I was hoping to find something substatial, but in the end it sadly just showed the lack of knowledge of the writes part. Especially since he could not even read the documentation for ftpd: &lt;a href="http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.cmds/doc/aixcmds2/ftpd.htm" rel="nofollow"&gt;http://publib.boulder.ibm.com/infocenter/pserie...&lt;/a&gt;&lt;br&gt;&lt;br&gt;And how can someone who claims to have read the AIX5L5.3 code, now even know that the command he propose would give root access, only give the user access as the AIX userid he used to logged in to the ftp server in the first place.&lt;br&gt;&lt;br&gt;It was a dissapointingly poor article.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Roden</dc:creator><pubDate>Fri, 17 Aug 2007 06:20:23 -0000</pubDate></item><item><title>Re: This Old Vulnerability: An AIX FTP client retrospective</title><link>http://www.matasano.com/log/923/this-old-vulnerability-an-aix-ftp-client-retrospective/#comment-2322989</link><description>Thank you, Dave. The top half of this post really made my morning. The bottom half was pretty good, too, but the top half was &lt;em&gt;inspired&lt;/em&gt;.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt</dc:creator><pubDate>Mon, 30 Jul 2007 14:43:50 -0000</pubDate></item><item><title>Re: This Old Vulnerability: An AIX FTP client retrospective</title><link>http://www.matasano.com/log/923/this-old-vulnerability-an-aix-ftp-client-retrospective/#comment-2322988</link><description>I think the vendors of the non-Linux Unices have just decided "fuck it, no one cares."&lt;br&gt;&lt;br&gt;I've had colleagues at Sun and SGI explicitly say "no one cares about security."&lt;br&gt;&lt;br&gt;I kind of wonder if they're right.  I have this feeling (one that I cannot prove) that most folks buying an IRIX/AIX box these days are doing so to maintain some legacy mountain of twisty passages that it would be incredibly painful to move away from.  The vendors price accordingly.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan Weber</dc:creator><pubDate>Mon, 30 Jul 2007 08:50:10 -0000</pubDate></item></channel></rss>