-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =============================================================================== >> CERT-NL, 01-Mar-2000 << >> All CERT-NL information has been moved to http://cert.surfnet.nl. Links << >> to CERT-NL information contained in this advisory are therefore outdated. << >> << >> CERT-NL also has stopped the CERT-CC-Mirror service. Due to this the << >> links to the CERT-CC mirror are obsolete. Visit the CERT-CC site for the << >> complete CERT-CC advisory texts: http://www.cert.org << =============================================================================== =============================================================================== Security Advisory CERT-NL =============================================================================== Author/Source : DEC SSRT-US Index : S-92-16 Distribution : SURFnet Constituency Page : 1 Classification: External Version: final Subject : Potential Security Vulnerability Date : 25-aug-92 Identified in Monitor (VMS) =============================================================================== CERT-NL (SURFnet Computer Emergency Response Team) has received information concerning a security problem in Digital Equipoment Corporation VMS Monitor. CERT-NL wishes to thank DEC SSRT-US for bringing this to our attention. =============================================================================== SSRT-0200 PROBLEM: Potential Security Vulnerability Identified in Monitor SOURCE: Digital Equipment Corporation AUTHOR: Software Security Response Team - U.S. Colorado Springs USA PRODUCT: VMS Symptoms Identified On: VMS, Versions 5.0, 5.0-1, 5.0-2, 5.1, 5.1-B, 5.1-1, 5.1-2, 5.2, 5.2-1, 5.3, 5.3-1, 5.3-2, 5.4, 5.4-1, 5.4-2 ******************************************************* SOLUTION: This problem is not present in VMS V5.4-3 (released in October 1991) through V5.5-1 (released in July, 1992.) ******************************************************* Copyright (c) Digital Equipment Corporation, 1992 All Rights Reserved. Published Rights Reserved Under The Copyright Laws Of The United States. - ------------------------------------------------------------------------------- PROBLEM/IMPACT: - ------------------------------------------------------------------------------- Unauthorized privileges may be expanded to authorized users of a system under certain conditions, via the Monitor utility. Should a system be compromised through unauthorized access, there is a risk of potential damage to a system environment. This problem will not permit unauthorized access entry, as individuals attempting to gain unauthorized access will continue to be denied through the standard VMS security mechanisms. - ------------------------------------------------------------------------------- SOLUTION: - ------------------------------------------------------------------------------- This potential vulnerability does not exist in VMS V5.4-3 (released in October 1991) and later versions of VMS through V5.5-1. Digital strongly recommends that you upgrade to a minimum of VMS V5.4-3, and further, to the latest release of VMS V5.5-1. (released in July, 1992) - ------------------------------------------------------------------------------- INFORMATION: - ------------------------------------------------------------------------------- If you cannot upgrade at this time Digital recommends that you implement a workaround (examples attached below) to avoid any potential vulnerability. As always, Digital recommends that you periodically review your system management and security procedures. Digital will continue to review and enhance the security features of its products and work with customers to maintain and improve the security and integrity of their systems. - ------------------------------------------------------------------------------- WORKAROUND - ------------------------------------------------------------------------------- A suggested workaround would be to remove the installed image SYS$SHARE:SPISHR.EXE via VMS INSTALL and/or restrict the use of the MONITOR utility to "privileged" system administrators. Below are the examples of doing both; [1] To disable the MONITOR utility the image SYS$SHARE:SPISHR.EXE should be deinstalled. From a privileged account; For cluster configurations; --------------------------- $ MC SYSMAN SYSMAN> SET ENVIRONMENT/CLUSTER SYSMAN> DO INSTALL REMOVE SYS$SHARE:SPISHR.EXE SYSMAN> DO RENAME SYS$SHARE:SPISHR.EXE SPISHR.HOLD SYSMAN> EXIT For non-VAXcluster configurations; --------------------------------- $INSTALL INSTALL>REMOVE SYS$SHARE:SPISHR.EXE INSTALL>EXIT $RENAME SYS$SHARE:SPISHR.EXE SPISHR.HOLD [2] If you wish to restrict access to the MONITOR command so that only a limited number of authorized (or privileged) persons are granted access to the utility, one method might be to issue the following example commands; From a privileged account; For cluster configurations; --------------------------- $ MC SYSMAN SYSMAN> SET ENVIRONMENT/CLUSTER SYSMAN> DO INSTALL REMOVE SYS$SHARE:SPISHR.EXE SYSMAN> DO SET FILE/ACL=(ID=*,ACCESS=NONE) SYS$SHARE:SPISHR.EXE SYSMAN> DO SET FILE/ACL=(ID=SYSTEM,ACCESS=READ+EXECUTE) SYS$SHARE:SPISHR.EXE SYSMAN> DO INSTALL ADD SYS$SHARE:SPISHR.EXE/OPEN/HEADER/SHARE/PROTECT SYSMAN> EXIT $ THIS WILL IMPACT the MONITOR UTILITY FOR REMOTE MONITORING. LOCAL MONITORING WILL CONTINUE TO WORK FOR PERSONS HOLDING THE ID's GRANTED ACL ACCESS. see additional note(s) below For non-VAXcluster configurations; ---------------------------------- $ INSTALL INSTALL>REMOVE SYS$SHARE:SPISHR.EXE INSTALL>EXIT $ SET FILE /ACL=(ID=*,ACCESS=NONE) SYS$SHARE:SPISHR.EXE $ SET FILE /ACL=(ID=SYSTEM,ACCESS=READ+EXECUTE) SYS$SHARE:SPISHR.EXE $ INSTALL INSTALL>ADD SYS$SHARE:SPISHR.EXE/OPEN/HEADER/SHARE/PROTECT INSTALL>EXIT $ IN THE ABOVE EXAMPLES, THE "SET FILE /ACL" LINE SHOULD BE REPEATED FOR ALL ACCOUNTS THAT ARE REQUIRED/ALLOWED TO USE THE DCL MONITOR COMMAND. NOTE: The ID -SYSTEM- is an example, and should be substituted as necessary with valid user ID's that are associated with accounts you wish to grant access to. ============================================================================== CERT-NL is the Computer Emergency Response Team for SURFnet customers. SURFnet is the Dutch network for educational, research and related institutes. CERT-NL is a member of the Forum of Incident Response and Security Teams (FIRST). All CERT-NL material is available under: http://cert.surfnet.nl/ In case of computer or network security problems please contact your local CERT/security-team or CERT-NL (if your institute is NOT a SURFnet customer please address the appropriate (local) CERT/security-team). CERT-NL is one/two hour(s) ahead of UTC (GMT) in winter/summer, i.e. UTC+0100 in winter and UTC+0200 in summer (DST). Email: cert-nl@surfnet.nl ATTENDED REGULARLY ALL DAYS Phone: +31 302 305 305 BUSINESS HOURS ONLY Fax: +31 302 305 329 BUSINESS HOURS ONLY Snailmail: SURFnet bv Attn. CERT-NL P.O. Box 19035 NL - 3501 DA UTRECHT The Netherlands NOODGEVALLEN: 06 22 92 35 64 ALTIJD BEREIKBAAR EMERGENCIES : +31 6 22 92 35 64 ATTENDED AT ALL TIMES CERT-NL'S EMERGENCY PHONENUMBER IS ONLY TO BE USED IN CASE OF EMERGENCIES: THE SURFNET HELPDESK OPERATING THE EMERGENCY NUMBER HAS A *FIXED* PROCEDURE FOR DEALING WITH YOUR ALERT AND WILL IN REGULAR CASES RELAY IT TO CERT-NL IN AN APPROPRIATE MANNER. CERT-NL WILL THEN CONTACT YOU. =============================================================================== -----BEGIN PGP SIGNATURE----- Version: PGP 6.5.1i iQA/AwUBOL6V+jSYjBqwfc9jEQIdiwCgtpU4geDuzvix2civ+DhPDW3kMP8An2Zi gLtW2+NWbnX/GSdW3RH67Nzr =xnbA -----END PGP SIGNATURE-----