| View previous topic :: View next topic   | 
	
	
	
		| Author | 
		Message | 
	
	
		edvallie Put Beer Here
  
  Joined: 07 Aug 2005 Posts: 1255 Location: Computer
  | 
		
			
				 Posted: Mon, 12 Feb 2007 23:15:21    Post Subject: HUGE Solaris Exploit | 
				       | 
			 
			
				
  | 
			 
			
				Did anybody else read about this? I'm not sure if BB would appreciate posting the link to the actual exploit here, but a warning to all disable telnet on any solaris boxes that you're in control of.
 
 
What do you guys make of it? Pretty embarrasing imo...
 
 
Linkage: 
 
 
http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html _________________ ABAP? What did you call me?
  Last edited by edvallie on Mon, 12 Feb 2007 23:30:23; edited 1 time in total  | 
			 
		  | 
	
	
		| Back to top | 
		 | 
	
	
		  | 
	
	
		Little Bruin 
Boo Boo
  
Joined: 07 Apr 2003 
Posts: 667 
Location: Pic-A-Nic Basket | 
		
			
		 | 
	
	
		  | 
	
	
		JimBowy Moderator
  
  Joined: 02 Aug 2003 Posts: 1627
 
  | 
		 | 
	
	
		| Back to top | 
		 | 
	
	
		  | 
	
	
		edvallie Put Beer Here
  
  Joined: 07 Aug 2005 Posts: 1255 Location: Computer
  | 
		 | 
	
	
		| Back to top | 
		 | 
	
	
		  | 
	
	
		Blue|Fusion Rated XXX
  
  Joined: 30 May 2005 Posts: 441 Location: Cleveland, OH
  | 
		
			
				 Posted: Tue, 13 Feb 2007 09:51:20    Post Subject:  | 
				       | 
			 
			
				
  | 
			 
			
				It is indeed a rather bad exploit.  Another reason I always disable Telnet on Linux right after installation.  SSH with RSA key's baby!  Screw passwords!
 
 
P.S.  I'm so excited my University has canceled today!!! _________________ 5 home-built PCs, ASUS A6Jc Laptop, and a PowerEdge 2650 - all running Gentoo.   Now if only I can get a car and plane to run it.  Take a look at my Gallery!  | 
			 
		  | 
	
	
		| Back to top | 
		 | 
	
	
		  | 
	
	
		edvallie Put Beer Here
  
  Joined: 07 Aug 2005 Posts: 1255 Location: Computer
  | 
		
			
				 Posted: Tue, 13 Feb 2007 09:59:08    Post Subject:  | 
				       | 
			 
			
				
  | 
			 
			
				 	  | Blue|Fusion wrote: | 	 		  It is indeed a rather bad exploit.  Another reason I always disable Telnet on Linux right after installation.  SSH with RSA key's baby!  Screw passwords!
 
 
P.S.  I'm so excited my University has canceled today!!! | 	  
 
 
w00t   _________________ ABAP? What did you call me? | 
			 
		  | 
	
	
		| Back to top | 
		 | 
	
	
		  | 
	
	
		BeerCheeze *hick*
  
  Joined: 14 Jun 2003 Posts: 9285 Location: At the Bar
  | 
		 | 
	
	
		| Back to top | 
		 | 
	
	
		  | 
	
	
		 |