The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Oracle installer problem


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Sun, 5 Mar 2000 18:32:06 -0800
From: Keyser Soze <ksoze@OBSCURITY.ORG>
To: BUGTRAQ@SECURITYFOCUS.COM
Subject: Oracle installer problem

-----BEGIN PGP SIGNED MESSAGE-----


greetings,

During the installation of Oracle 8.1.5.0.1 for Linux the installer
creates the directory /tmp/orainstall (owned by oracle:dba, mode 711).
Inside that directory it creates a shell script called orainstRoot.sh
(mode 777). After that, the installer stops and asks you to run this
script as root.

There are two big problems here:

1. The installer blindly writes to orainstRoot.sh without checking if it
exists, is a regular file or if it is even owned by oracle. An attacker
may be able to use this to gain access to the oracle account by creating a
.rhosts or .ssh/authorized_keys in oracle's home directory. After that
they could connect to your database as INTERNAL...

2. Any user can run shell commands as root by editing orainstRoot.sh
before root executes it.

I don't recommend installing Oracle on machines with user accounts, but if
you must you can eliminate this problem by creating /tmp/orainstall/
with proper permissions before you run the installer. So, for a typical
installation:

   mkdir /tmp/orainstall
   chmod 700 /tmp/orainstall
   chown oracle:dba /tmp/orainstall

(note: I found this using an 8.1.5i for Linux/Intel CD that Oracle shipped
me last week. The part number is F54997-01.)

ksoze


-----BEGIN PGP SIGNATURE-----
Version: 2.6.3a
Charset: noconv

iQCVAwUBOMMYrHEQwXQ+axAxAQHBEgQAgXsynBhLUcQivZSIuel2ykzMyW7m8a0o
RFi6xHDqJoK4s6Fedtx732QY780wh1UhIHsW45UP+MQKr7Q56BTGNfSmp+AXm2Mj
bMkyya0Cf/MkQa57HXLsKBLxQhJPCsXoM7adUd2fHC6W4pcT4sUrvB6g8axXXJqd
iQsG1Tku9f0=
=mvvI
-----END PGP SIGNATURE-----

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>

ПОДПИШИСЬ НА ЖУРНАЛ Linux Format 2012!

Журнал "Linux Format" (Линукс Формат)- Единственный в России и странах СНГ журнал на русском языке, посвящённый Linux и свободному ПО. Журнал для IT-директоров, IT-менеджеров, программистов, системных администраторов, учителей школ и преподавателей ВУЗов и всех пользователей ПК. В каждом выпуске: Новости индустрии OpenSource, обзоры новинок свободного ПО, обучающие и методические статьи.

Каждый, кто оформит подписку, получает бонусы и подарки- объёмные наклейки на системный блок, диск с архивом номеров за 2005-2011 г.г. и ежемесячно электронную версию журнала в pdf-формате.

Оформить подписку на год


  Закладки на сайте
  Проследить за страницей
Created 1996-2012 by Maxim Chirkov  
ДобавитьРекламаВебмастеруГИД  
RUNNet TopList