Sun's Solaris 10 at risk of zero-day exploit

By Dawn Kawamoto, CNET News.com
14 February 2007 09:10 AM
Tags: security, sun, telnet, unix, solaris, zero-day

update A patch for the Solaris 10 zero-day exploit, due to security bugs in its telnet service, is almost ready for release, according to an Australian staff engineer for Sun Microsystems.

Sun issued first issued a warning about the zero-day vulnerabilities in Solaris 10 and the beta version of Solaris 11 on Tuesday in the US.

The "highly critical" vulnerabilities could enable attackers to gain unauthorised access to a user's system without requiring the user to download exploit code, said Johannes Ullrich, chief research officer at the Sans Institute, which also issued a security advisory.

Attackers could exploit the so-called zero-day vulnerabilities via the telnet service if it is automatically enabled, the advisory said.

Telnet, which dates back to the early days of Unix, was one of the first methods devised to allow system administrators to remotely monitor their networks. The service will usually prompt people for their user name and password. However, security flaws in the operating system could allow an attacker to add additional parameters to connect to the remote telnet server without a user name or password, Ullrich noted.

Once attackers have gained access, they could execute arbitrary commands with the same privileges as the user.

"It's an ancient way to administer systems," Ullrich said. "There's no good reason to enable telnet on Solaris...All the communication with telnet is not encrypted. In recent years, other technologies have replaced it, like (encrypted communications through a secure shell) SSH."

Last month, Sun issued an update to Solaris 10, which now has the SSH enabled by default, said Bob Wientzen, Solaris spokesman for Sun. He added that the company is currently working on a fix for the telnet vulnerabilities.

Sun, in its security advisory, said the vulnerabilities are found in Solaris 10, running on Sparc servers, as well as on x86 servers.

The Sans Institute and Sun said they were not aware of any reports of systems exploited due to the security flaws in the telnet service.

If users must run Solaris with the telnet service enabled, Ullrich recommends using a firewall to limit connections to a user's telnet service. However, he said that while this workaround will prevent direct access to the root account, other accounts on a user's system could still be compromised.

Advertisement

Talkback 2 comments

    Sorry but "Ullrich" is full of crap. marekfoo at gmail dot com -- 14/02/07

    If users must run Solaris with the telnet service enabled, Ullrich recommends using a firewall to limit connections to a user's telnet service. However, he said that while this workaround will prevent direct access to the root account, other accounts on a user's system could still be compromised.

    That last quote is nonsense. If port 23 is firewalled off, how can remote attackers connect into it?

    Serious Solaris Deployments DON'T use Telnet David James -- 14/02/07

    Is this a joke?
    What serious Solaris person would use Telnet???

    After deploying enterprise infrastructure, most likely a multi-layer (web/app/db) system designed for high availability and large transaction count... why the hell would you open telnet ????????????????

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Phil Dobbie A guide to the future of the internet
    Last week we looked at the history of the internet in Australia. It's been around for 20 years and changed our lives in so many ways. Imagine what it could do given another 20 years.
  • Array Carelessness busts Linux security
    No operating system can ever properly protect a computer from trojans as long as users continue to do silly things. Just because Linux is immune to your standard drive-by viruses it does not mean that it can escape trojan horses.
  • Array Sun shining on Ajnaware
    Graham Dawson talks about the future of iPhone app development and augmented reality.
  • More blogs »

Tags

Back to top

Featured