Bug in Windows for Workgroups, Win95 beta
Dan Shearer (itudps@lux.levels.unisa.edu.au)
Sat, 22 Jul 1995 12:42:25 +0930
* Messages sorted by: [ date ][ thread ][ subject ][ author ]
* Next message: Dan Shearer: "Re: Bug in Windows for Workgroups, Win95
beta"
* Previous message: Cy Schubert - BCSC Open Systems Group: "Re:
[Linux-ISP] lpr(1) bug"
* Next in thread: Dan Shearer: "Re: Bug in Windows for Workgroups,
Win95 beta"
This is probably getting a bit stale by now, but I haven't seen it here.
The Samba development community have discovered a security hole in
Workgroups and Win95 beta. Microsoft were officially informed, and
appear to have fixed the problem in the release version of Windows 95.
It still exists in Windows for Workgroups, and last I heard Microsoft
were not committing to releasing a patch for the problem, but they didn't
say they wouldn't either.
Affects
-------
Any machine with Windows for Workgroups that is running TCP/IP as a
file/print transport. Certainly Microsoft TCP/IP and most likely other
stacks as well.
Effects
-------
If the Workgroups machine shares any directory below root, a free Unix
program that uses the Microsoft SMB protocol over TCP/IP can access the
whole drive, with whatever permissions the sharename was given. These
resources are advertised on a browse list that is made available to anyone
on the local network by default, and to anyone on the Internet who knows
the machine's IP address. Any user sharing anything without a password is
automatically opening the whole disk to the whole internet (for those
that can locate the machine) and those with a password should be aware
that Workgroups has no protection against brute force attacks.
To Reproduce
------------
Start up "smbclient", and ask to connect to a resource. Then issue the
commands "cd ../" or "cd ...", which are valid according to the SMB
protocol. These servers move up to the next level directory (the one above
the one that was shared on the network) without any complaint. I have
tried other SMB servers such as Samba, Windows NT and OS/2 LAN Manager.
Samba correctly denies access, NT incorrectly does not complain but does
not appear to have a security problem, and LAN Manager handles it in the
correct manner.
Why
---
The Microsft Server Message Block (SMB) file and print sharing protocol is
an X/Open standard. The Samba client implements the X/Open protocol
properly, but these two Microsoft servers do not. As Andrew Tridgell said
recently "It is nice of them to make it an X/Open standard, but as with
most proprietry ideas it is much less rigorously tested than an RFC. For
instance, there are three completely different date and time formats used
at random throughout". So I suppose it is just the same sort of thinking
carried into implementation.
Samba
-----
You can find out about Samba at
http://lake.canberra.edu.au/pub/samba/samba.html.
Exploration
-----------
The Samba site has a link to the tcpdump patches by Andrew that understand
SMB (and also NetBEUI, incidentally.)
Samba also comes with a file system for Linux that allows SMB resources
to be mounted. Theoretically it would be possible to mount the disk of a
Workgroups server and reshare it as, say, an FTP site or a Web site :-)
Dan
* Next message: Dan Shearer: "Re: Bug in Windows for Workgroups, Win95
beta"
* Previous message: Cy Schubert - BCSC Open Systems Group: "Re:
[Linux-ISP] lpr(1) bug"
* Next in thread: Dan Shearer: "Re: Bug in Windows for Workgroups,
Win95 beta"
This page was created Wed Aug 11 23:48:21 EDT 1999
Using Linux
version 2.0.32
on an i586
Main Page @ Matarese.com
The Myth of the 2600Hz Detector @ Matarese.com
Acquiring Account Information @ Matarese.com
Act2! by Symantec @ Matarese.com
All hacks / Annoyance @ Matarese.com
Alt 2600 Group FAQ @ Matarese.com
Hacking Angelfire @ Matarese.com
Anonymous E-Mail @ Matarese.com
Anonymous FTP: Frequently Asked Questions (FAQ) @ Matarese.com
Maintaining Access - Implementing Backdoors @ Matarese.com
How to Receive Banned Newsgroups FAQ @ Matarese.com
Hacking BBS's @ Matarese.com
phreaking tutorial @ Matarese.com
The Bluebox @ Matarese.com
List of Common Bugs @ Matarese.com
Things that go Bump on the Internet @ Matarese.com
Hacking Calling Cards @ Matarese.com
Expanding the capacity of Caller ID Boxes @ Matarese.com
What is Caller-ID? @ Matarese.com
Hacking Call Back Verify @ Matarese.com
CULT OF THE DEAD COW @ Matarese.com
Cellular Roaming: The New Deals @ Matarese.com
CELLULAR TELEPHONE PHREAKING PHILE SERIES @ Matarese.com
Cracking Unix passwords @ Matarese.com
Hacking Webpages @ Matarese.com
The Matarese Circle @ Matarese.com
Cisco Password Cracking Script @ Matarese.com
Customer Name and Address @ Matarese.com
Cops and Robbers | UNIX Security @ Matarese.com
Cracking NT Passwords @ Matarese.com
Odins cracking/coding and PPE resources @ Matarese.com
Credit Carding Part I @ Matarese.com
How do I defeat Copy Protection? @ Matarese.com
What are the DTMF frequencies? @ Matarese.com
Exploits FAQ @ Matarese.com
Making Free Calls @ Matarese.com
FTP Bouncing @ Matarese.com
Hackers Encyclopedia @ Matarese.com
The Conscience of a Hacker / Hacker Manifesto @ Matarese.com
Hacking from Windows9x FTP @ Matarese.com
Hacking Tripod @ Matarese.com
Hacking Web Pages @ Matarese.com
How to crack a UNIX password file. @ Matarese.com
Hacking Servers : A Begginners Guide @ Matarese.com
TIPS FOR TRACKING HACKERS @ Matarese.com
Hacking Tutorial @ Matarese.com
Hacking UNIX @ Matarese.com
How to Hack the WWWboard Message Board 2.0 @ Matarese.com
Hackers Handbook @ Matarese.com
Guide to Harmless-Hacking @ Matarese.com
All about security holes @ Matarese.com
Hacking Hotmail @ Matarese.com
How to crack by +ORC complete tutorial in one file (BIG!) @ Matarese.com
]How to Hack from from Harlequin and Archangel @ Matarese.com
Improve security by breaking into your site @ Matarese.com
Ch1can0 BEOWULF @ Matarese.com
Internet Security @ Matarese.com
Bugs and Backdoors in IRC clients, scripts and bots @ Matarese.com
IRC Hacking @ Matarese.com
FAQ for Trading For FileZ in IRC @ Matarese.com
Creating a Xdcc offer bot for irc @ Matarese.com
Integrated Systems Digital Network @ Matarese.com
Everything you should know about computer viruses @ Matarese.com
Lan Technology Scorecard @ Matarese.com
Local Area Signalling Services (LASS) and Custom Calling Feature Control Codes @ Matarese.com
Harmless Hacking - Linux @ Matarese.com
INDEX @ Matarese.com
Loops wanted! @ Matarese.com
Mail Spoofing Explained @ Matarese.com
Microsoft IIS Vulnerability @ Matarese.com
Microsoft(Yuk) Index Server exposes IDs and Passwords @ Matarese.com
Intresting Microsoft Access 7.0 Trick @ Matarese.com
MS Money 2.0 Back Door @ Matarese.com
Mind Your Own Business (MYOB) @ Matarese.com
Nameserver listing! @ Matarese.com
Newbies handbook / HOW TO BEGIN IN THE WORLD OF H/P @ Matarese.com
Bugs in Windows NT (Too many to list here completely...) @ Matarese.com
This Hack is for the OptiChat Original Chat Room @ Matarese.com
Internet Outdials @ Matarese.com
Pager Frequencies @ Matarese.com
Password Recovery Techniques @ Matarese.com
How to Steal Local Calls from Most Payphones @ Matarese.com
PBX's (Private Branch Exchanges) and WATS @ Matarese.com
Cryptography / PGP @ Matarese.com
The PHF bug @ Matarese.com
Introduction to the Internet Protocols @ Matarese.com
Analysis of QueSO Performance @ Matarese.com
Finger - ATTACKING FROM THE OUTSIDE @ Matarese.com
The PPP protocol (Point-to-Point Protocol) @ Matarese.com
Scam news / Hacking / Phreaking / Anarchy / Virii @ Matarese.com
Hacking your school computers @ Matarese.com
L0pht Security Advisory - Sendmail 8.7.5 @ Matarese.com
Sniffer FAQ V 1.7 @ Matarese.com
THE COMPLETE SOCIAL ENGINEERING FAQ! @ Matarese.com
Socket Services @ Matarese.com
Softice Manual @ Matarese.com
Softice Manual 2 @ Matarese.com
Softice Manual 3 @ Matarese.com
Softice Manual 4 @ Matarese.com
Softice Manual 5 @ Matarese.com
SSPING/JOLT patches @ Matarese.com
THE ULTIMATE BEGINNER'S GUIDE TO HACKING AND PHREAKING @ Matarese.com
@ Matarese.com
@ Matarese.com
TCP/IP Services (Phrack Stuff) @ Matarese.com
Telenet The Secret Exposed @ Matarese.com
WORKING OUT-TELNETS @ Matarese.com
Covering your tracks, Theory @ Matarese.com
How to defeat the Tripod Advertisement on your webpage. @ Matarese.com
BT Basics @ Matarese.com
BT Phreaking @ Matarese.com
The Psychotic Internet Services' Unix Bible @ Matarese.com
The Psychotic Internet Services' Unix Bible @ Matarese.com
UNIX FAQ @ Matarese.com
Gibe's UNIX COMMAND Bible @ Matarese.com
How to become a Unix Hacker @ Matarese.com
Cracking that Passwd File @ Matarese.com
Hacking Commands, and Some Hints On Their Usage @ Matarese.com
How do I post to a moderated newsgroup? @ Matarese.com
Virii 101 @ Matarese.com
What You Should Know About Computer Viruses @ Matarese.com
How can I protect myself from viruses and such? @ Matarese.com
What is a trojan/worm/virus/logic bomb? @ Matarese.com
VMS Info (Password Cracking) @ Matarese.com
HACKING THE WAL-MART ARMORGUARD COMPUTER PROTECTION SYSTEM @ Matarese.com
Using web proxies to disguise your IP address @ Matarese.com
Dig up hidden CD Keys @ Matarese.com
X-Windows Security @ Matarese.com
Copyright (C) 1999 - Matarese.com