Firms fall through Unix security flaw

Solaris and Mandrake *nixed, but SuSE and Irix could also be affected

Written by Andy McCue

A fifth of large corporate users could be vulnerable to a newly discovered security flaw that allows hackers to gain remote control of Unix boxes running Solaris and MandrakeSoft's Linux distro.

The flaw was discovered by UK security consultancy ProCheckUp which released the details before official Cert verification, because a freely available hacker's scanner was found to be already searching for the hole.

The problem centres on the default configuration of the X Display Manager Control Protocol (XDMCP), which allows remote access.

When this is enabled, hackers can gain access and are presented with a graphical list of users and usernames on that box. They only have to crack the password to take control.

"It gives someone remote control over your desktop and machine without you knowing it, which is serious," said Richard Brain, technical director at ProCheckUp.

Brain discovered the hole during testing of a customer's internet-connected servers. "We are looking at about 20 per cent of our big clients with their own DNS servers that are vulnerable," he said.

The problem has been confirmed on Unix boxes running all versions of Sun Solaris and versions of Linux Mandrake up to 8.1. But Brain is now investigating reports it also affects SuSE Linux and Irix.

If the server sits behind a properly configured firewall, that will give further protection, but ultimately remote access needs to be disabled and traffic blocked on the ports used by the XDMCP protocol.

This is a relatively easy task for IT managers, and the remote connections can be disabled in seconds by simply changing the configuration of the XDMCP server.

Full details of the vulnerability and how to fix it are available here

Tags:

Further reading

Linux Special: 2002 the year of the Penguin

Thumbs up for Linux over the last 12 months. But will 2002 finally be the year of the Penguin?   More...

SSH flaw puts Unix users at risk

Latest version vulnerable to attack   More...

Related articles

Debian flaw exposes communications breakdown

A wake up call for open source developers, Gartner warns   More...

SuSE patches 'highly critical' Java flaw

Remote system access possible unless update is applied   More...

Microsoft warns of web proxy flaw

Possible risk of 'man-in-the-middle' attack   More...

Sun patches 'critical' Java flaws

Problems with JDK, JRE and SDK   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement