:


Original is at Open Systems. Nets: #6/96
http://www.osp.ru/nets/1996/06/source/51.html


· # 6/96 · . 51-56


Unix
.
Unix
ftp- HTTP- CGI
NFS/NIS
SUID
?

, Internet. , .

Internet. . , (!) , . Internet ( , Firewall - T-).

- . , account ( , . , - - ). , - - , IRC- .. account- Unix , IRC . , - (, , , . , , ).

, . , , , ( ), IRC. , - " ? !" . , , .

, Internet , , .

account , Internet Sun, NFS. account . (, - !) - NFS ~/.rhosts "+", rlogin. . (, - "rm -rf /").

.

  • Internet, , . .
  • Internet Unix - . - , . - .
  • "" ( NFS Rlogin) Internet. , , , .
  • , , , , Internet. , , - ( - - -, ), "IP ", .. - , , ( - ), , , , ), $15-20 . . , , , , Internet - (http://www.playboy.com), , http://altavista.digital.com .

    Picture

    .

    , , . . , , . . "Firewall" .

    - , , , , - . Internet .

    Unix

    Unix . Internet . Internet Unix . Unix , Internet, . - ( ) Unix . Unix .

    , Unix , , . WYSIWYG - What You Say Is What You Get.

    Unix . () , - . () , . , , , (Mr. Charlie Root). , , . , , - ( , , , , ).

    , , . , /etc/passwd . ( , , ). , (uid 0). , , . . , - , . ( ) . , , Unix.

    , . Unix (SUID), (SUID root). . (uid 0) , , . , Shell. , Shell, - . , .

    , . , .

    , 咄 (inetd) , (suid 0). 1024 ( Unix , . , ).

    , - Unix , , , . , . , , . , Unix. , . , , . (r-commands), . , , .

    Unix

    , Unix , . , , . , . , . . , .

    , , , . , .

    , Unix,

  • , ;
  • , ;
  • (, guest guest);
  • ;
  • (, );
  • , " ";
  • ;
  • , , ;
  • Unix (- , - Unix);
  • , .
  • Unix - , . - , , , , . - Plan 9 - , .

    , . , "aaa", "qqq", "123456", "password" ! , . . , , - , ( , , , ) ( ). , ( ). - . - - , 10 . .

    , "qqq". "Crack" (ftp://info.cert.org/pub/ tools/crack/crack_4.1-tar.Z), . , , . , . , , Perl , Intel. crack . Intel . , . - .

    - , - . . - . - .

    , . , . , , . (S/Key) - , . S/Key , , FreeBSD.

    ftp- HTTP- CGI

    HTTP- Internet . , . - , - . . , . CGI- .

    HTTP- /etc/passwd ( Apache CGI- "phf", ). , .

    Web-:

  • HTTP
  • root
  • CGI, .
  • CGI .
  • , , (, `<>;").

    FTP-. , FTP- / . DOS, OS/2 Windows"95, , NFS, . FTP , "" ( ) .

    , , , , - HTTP, FTP . . HTTP FTP .

    NFS/NIS

    NFS . , . Intranet, . , . NFS , NIS Unix " ". , NFS ( TCP UDP 111 2049) .

    . , ( ) gets() puts(), , . ( , 1988 Unix, Internet. , National Security Agency (NSA - . , NSA "No Such Agency").

    . , . SUID- , - .

    SUID

    CERT (Computer Emergency Respond Team) SUID-. .

    , Unix - ( , , ). ? , , (, MULTICS, Windows NT) , . , , . "C2 certified", (, . , "Windows"95 Compatible" .

    , , "Firewall" - , ( , . , "" ). , ?

    Unix-, FreeBSD BSDI/OS (tcp_wrappers, TIS Firewall Toolkit, tripwire, COPS, ..). , . .

    - . , , - Internet! . ?

    Windows Expo"96 Micrisoft - - DEC Firewall NT Microsoft Proxy - , . , , .

    , , - " ". , - , .

    , . , , , . - . . - .

    , , . Firewall . , , . , , . , .

    . , IP/TCP/UDP , . Proxy- . , . proxy- , . . , proxy-.

    . - , , , . , , . , .

    firewalls@GreatCircle.com. . . - !

    ?

    , ! , , .

    [ ]

    http://www.cert.org
    http://www.cs.purdue.edu/homes/spaf/hotlist/csec-top.html
    http://ciac.llnl.gov
    http://csrc.ncsl.nist.gov/first
    http://www.alw.nih.gov/Security/security.html
    http://www.auscert.org.au
    http://www.cert.dfn.de/eng
    http://www.cs.purdue.edu/coast/coast.html
    http://www.sware.com/
    http://www.telstra.com.au/info/security.html
    http://www.raptor.com/library/library.

    - Stins Coman. : akolb@stins.msk.su.


    · # 6/96

    Last-modified: Fri, 03 Jul 1998 04:50:06 GMT
    :