Koozali.org: home of the SME Server

rootkit hunter 1.1.15 output

Offline Denbert

  • *
  • 156
  • +0/-0
    • hegnstoften.net
rootkit hunter 1.1.15 output
« on: August 13, 2004, 06:52:09 AM »
Hi there,

When I run RootKit Hunter I get this answer:

* Application version scan
   - ClamAV 0.65   [ Vulnerable ]
   - GnuPG 1.0.7   [ Vulnerable ]
   - Apache 1.3.27   [ Vulnerable ]
   - Bind DNS [unknown]   [ OK ]
   - OpenSSL 0.9.6b   [ Unknown ]
   - PHP 4.3.6   [ Vulnerable ]
   - Procmail MTA 3.22   [ OK ]
   - ProFTPd 1.2.9   [ Vulnerable ]
   - OpenSSH 3.8p1   [ OK ]

Shouldn’t these applications be updated or are they safe in the SME 6.0.1 Server-gateway configuration?

Furthermore there should be a forum called security for these issues.
/ Denbert
"Success is not final, failure is not fatal: it is the courage to continue that counts" - Sir Winston Churchill

mbachmann

rootkit hunter 1.1.15 output
« Reply #1 on: August 23, 2004, 05:11:59 PM »
Switch off ssh and ftp access or allow only from local networks. Close down apache. That's the price for security.

GetRighT

rootkit hunter 1.1.15 output
« Reply #2 on: August 29, 2004, 01:18:28 AM »
Quote from: "mbachmann"
Switch off ssh and ftp access or allow only from local networks. Close down apache. That's the price for security.


Erhmm... then why have a server connected to the internet... doh?  :hammer:

Offline Denbert

  • *
  • 156
  • +0/-0
    • hegnstoften.net
rootkit hunter 1.1.15 output
« Reply #3 on: August 29, 2004, 10:30:53 AM »
You took the words right out of my mouth. It’s no solution to “unplug” the server.

I’m looking forward to follow the work from the new security team. And hope that they will deal more serious about security issues.

Cheers.
/ Denbert
"Success is not final, failure is not fatal: it is the courage to continue that counts" - Sir Winston Churchill

guest22

rootkit hunter 1.1.15 output
« Reply #4 on: August 31, 2004, 12:45:28 AM »
Is this report based on THE standard SME Server 6.0.1-1 or did you install 3rd party contribs?

If you did install 3rd party contribs, please contact the author of that specific contrib to ask him/her about the messages.

If the messages are about a DEFAULT installation of SME Server 6.0.1-1 please report them in the bug tracker 1 at a time so seperate issues can be tracked in seperate bugreports.

Thanks,
RequestedDeletion

Offline Denbert

  • *
  • 156
  • +0/-0
    • hegnstoften.net
rootkit hunter 1.1.15 output
« Reply #5 on: August 31, 2004, 12:09:22 PM »
Quote from: "guest22"
Is this report based on THE standard SME Server 6.0.1-1 or did you install 3rd party contribs?

RequestedDeletion


Ok, I have some contribs installed – I’ll setup at clean testbox and make a new report one of these days.

Cheers,
/ Denbert
"Success is not final, failure is not fatal: it is the courage to continue that counts" - Sir Winston Churchill

Offline byte

  • *
  • 2,183
  • +2/-0
rootkit hunter 1.1.15 output
« Reply #6 on: August 31, 2004, 12:13:07 PM »
I'd Say with the Exception of CLAM rest are DEFAULT...

Is'nt it a security related problem? not a bug!
--[byte]--

Have you filled in a Bug Report over @ http://bugs.contribs.org ? Please don't wait to be told this way you help us to help you/others - Thanks!

Offline Denbert

  • *
  • 156
  • +0/-0
    • hegnstoften.net
rootkit hunter 1.1.15 output
« Reply #7 on: August 31, 2004, 12:20:32 PM »
Quote from: "byte"

Is'nt it a security related problem? not a bug!


You are quite right – But there isn’t a forum called Security?

That’s why I placed the thread in here.

I’ll be back :-o
/ Denbert
"Success is not final, failure is not fatal: it is the courage to continue that counts" - Sir Winston Churchill

Offline sqlerror

  • ***
  • 50
  • +0/-0
Re: rootkit hunter 1.1.15 output
« Reply #8 on: November 02, 2004, 12:30:56 PM »
Quote from: "Denbert"
Hi there,

When I run RootKit Hunter I get this answer:

* Application version scan
   - ClamAV 0.65   [ Vulnerable ]
   - GnuPG 1.0.7   [ Vulnerable ]
   - Apache 1.3.27   [ Vulnerable ]
   - Bind DNS [unknown]   [ OK ]
   - OpenSSL 0.9.6b   [ Unknown ]
   - PHP 4.3.6   [ Vulnerable ]
   - Procmail MTA 3.22   [ OK ]
   - ProFTPd 1.2.9   [ Vulnerable ]
   - OpenSSH 3.8p1   [ OK ]

See my post on the same subject with a solution in the form of updated rpm's to address these vulnerabilities:
http://forums.contribs.org/index.php?topic=24329.0
Sqlerror

Offline sqlerror

  • ***
  • 50
  • +0/-0
Re: rootkit hunter 1.1.15 output
« Reply #9 on: November 02, 2004, 12:32:26 PM »
Quote from: "Denbert"
Hi there,

When I run RootKit Hunter I get this answer:

* Application version scan
   - ClamAV 0.65   [ Vulnerable ]
   - GnuPG 1.0.7   [ Vulnerable ]
   - Apache 1.3.27   [ Vulnerable ]
   - Bind DNS [unknown]   [ OK ]
   - OpenSSL 0.9.6b   [ Unknown ]
   - PHP 4.3.6   [ Vulnerable ]
   - Procmail MTA 3.22   [ OK ]
   - ProFTPd 1.2.9   [ Vulnerable ]
   - OpenSSH 3.8p1   [ OK ]

See my post on the same subject with a solution in the form of updated rpm's to address these vulnerabilities:
http://forums.contribs.org/index.php?topic=23241.0
Sqlerror