Archives

April 2004 (7)
March 2004 (12)
February 2004 (12)
January 2004 (22)
December 2003 (19)
November 2003 (16)
October 2003 (26)
September 2003 (18)
August 2003 (38)
July 2003 (80)
June 2003 (13)
May 2003 (24)
April 2003 (76)
March 2003 (75)
February 2003 (51)
January 2003 (73)

Category

Family (5)
FYI (18)
Games (2)
Geek (88)
Geographic (3)
Hacks (13)
Home (15)
Humor (54)
Ideas (20)
Ideaspace (15)
Local (15)
Metadata (10)
Microsoft (2)
MovableType (5)
Nitwits (66)
PKI (2)
Politics (22)
Quotes (3)
RDF (15)
RSS (4)
Security (3)
Semantic Web (13)
Site Info (13)
Social Networks (1)
Spam (9)
Sysadmin (1)
Tips (2)
Tivo (2)
TMFTOTHD (1)
To Do (1)
Unlisted (1)
Web (3)
Windows (1)

Local

« MetroBlogs »
DC metroblogs
beltway bloggers

Links


Assorted bits

Blogroll Me!
GeoURL
Listed on BlogShares




October 07, 2003

Heinous security hack thanks to MT

If you install MT as a user with shell login privileges, you're inviting possible disaster.

Basically there's a way, simply by editing templates (and thus files), to get MT to write some files and execute a daemon that'll let you login to a shell without authentication.

What you can do to avoid this risk is BE SURE that the files MT uses for code are not writable by the user that's running them inside the apache daemon. Likewise make sure the directories are no more writable than absolutely necessary.

Now, I can say that I'm actually grateful MT allowed this. I had a box that had gotten it's ssh daemon completely screwed up. Such that it refused to accept new logins. As a result I had to hack around trying to wedge a way into the box. MT let me get the right things created in the right places such that I could jumpstart a way into the box. This was good for me but bad overall.

I'm thinking some extra chattr or even chroot'ing steps are going to be a really good idea for MT installs...

Geek
Perma  | TrackBack (0) | 11:46 AM  | xml

Navigation

Recent Entries

America and Europe: Vive la différence?
Server changes afoot
Diet behavior mod
Googling for sensitive info
Outlook 2003 and IMAP, a marriage made in Hell
Bike to Work Day, May 7th
Speakeasy rocks
Zippo USB?
When geographic data is nowhere 'near' correct
Local campaign contributions

User comments
Trackbacks

Contact

send me an e-mail E-mail
chat with me using MS messenger MSN Messenger
chat with me via AIM America Online
chat with me on ICQ ICQ
chat with me on Yahoo! Yahoo
Add my vCard to your electronic addressbook vCard
Friend of a Friend FoaF

Syndication

XML  RDF  CDF

Comments

XFML

Extra Stuff

foaf
vCard
pgp info
Linked In
Powered by
Movable Type 2.64