On TechRepublic: Why Android beats iPhone
BNET Business Network:
BNET
TechRepublic
ZDNet

February 13th, 2007

Sun rushes out patch for Solaris Telnet exploit

Posted by Ryan Naraine @ 5:32 pm

Categories: Exploit code, Hackers, Patch Watch, Pen testing, Responsible disclosure, Uncategorized, Viruses and Worms, Vulnerability research

Tags: Telnet, Sun Microsystems Inc., Exploit, Sun Solaris, Ryan Naraine

Sun Microsystems has rushed out patches to fix a code execution hole in the Solaris 10/11 telnet daemon (in.telnetd).

The company's fix comes just days after a hacker known as "Kingcope" went public with details of the vulnerability, which allows a remote attacker to bypass the Sun Solaris telnet daemon's authentication mechanisms. It only affects systems which have the telnet(1) service enabled.

The patches can be downloaded here.

"[This] was an almighty cock up and should not have happened," said Alan Hargreaves, a staff engineer in Sun's systems technical support center.

In a blog entry that provides an excellent snapshot of the security patch-creation process at Sun, Hargreaves explained how the company reacted to the issue, which was publicly released without advance warning to the vendor.

"The upside to the posted exploit was the fact that because the code was available, the poster included an analysis of what was going wrong, pointing at the code that was broken. This almost certainly saved us some time in troubleshooting the issue. For this part of the post, you have my thanks. I would certainly be interested if the person who posted the exploit could tell us how he found the problem; for no other reason, than I'm simply interested."

Although patches have been shipped, security experts have one simple message to Solaris users: Turn off telnet and leave it off.

Telnet can be disabled by issuing the following command: # svcadm disable telnet

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 5 Talkback(s)
you missed the point
This is not only a root vulnerability.

The CONSOLE thing will only block the root exploit. If you only do that, you are still vulnerable for the bug to be used to gain access as other va... (Read the rest)
Posted by: tpenta Posted on: 02/14/07 You are currently: a Guest | | Terms of Use
In the future...  John L. Ries | 02/13/07
Good job on Sun  georgeou | 02/14/07
It IS disabled by default since S10U2  meh130@... | 02/14/07
you missed the point  tpenta | 02/14/07
formal patch can be downloaded at sunsolve  kfu070214 | 02/14/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads