Impact:
Intruders can exploit this vulnerability to modify the webpage and obtain the management right of the host.
Event Description:
On the attacked UNIX system, intruders often use the following
rpc.ttdbserverrpc.cmsdrpc.statd/automountdsadmind |
The BufferOverflow vulnerability of the program intrude the host remotely.
Solution:
1. Remove unnecessary RPCservice from/etc/inetd. conf. The removal method is
(1) edit/etc/inetd. conf and add "#" to unnecessary services or directly Delete and save the disks;
Kill-HUPinetd.pid.
2. Install patches
rpc.statd:OSVersionPatchID___________________SunOS5.6106592-02SunOS5.6_x86106593-02SunOS5.5.1104166-04SunOS5.5.1_x86104167-04SunOS5.5103468-04SunOS5.5_x86103469-05SunOS5.4102769-07SunOS5.4_x86102770-07SunOS5.3102932-05automountd:OSVersionPatchID___________________SunOS5.5.1104654-05SunOS5.5.1_x86104655-05SunOS5.5103187-43SunOS5.5_x86103188-43SunOS5.4101945-61SunOS5.4_x86101946-54SunOS5.3101318-92 |
Files can be downloaded at the following urls:
Ftp://sunsolve.sun.com/pub/patches
RedHat:
See the following URL:
Http://www.redhat.com/support/errata/RHSA-2000-043-03.HTML
Debian:
See the following URL:
Http://www.debian.org/security/2000/20000719a
(2) rpc. cmsd
Solaris:
Install the following patches according to your version
SunOSversionPatchID______________________5.7107893-045.7_x86107894-045.6105802-115.6_x86105803-135.5.1104489-105.5.1_x86105496-085.5104428-085.5_x86105495-065.4102734-05 |
Files can be downloaded at the following urls:
Ftp://sunsolve.sun.com/pub/patches
(3) rpc. ttdbserverd
Solaris:
Install the following patches according to your version
SunOSversionPatchID______________________5.7107893-045.7_x86107894-045.6105802-115.6_x86105803-135.5.1104489-105.5.1_x86105496-085.5104428-085.5_x86105495-065.4102734-05 |
Files can be downloaded at the following urls:
Ftp://sunsolve.sun.com/pub/patches
(4) sadmind
Solaris:
Install the following patches according to your version
OSVersionPatchID___________________SunOS5.7108662-01SunOS5.7_x86108663-01SunOS5.6108660-01SunOS5.6_x86108661-01SunOS5.5.1108658-01SunOS5.5.1_x86108659-01 |
Related Articles]
- Unix host Security Analysis Method
- Functions of Linux/unix Host loopback addresses