Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Enthusiast Zone > Networking > Malicious DHCP response can grant root access

Malicious DHCP response can grant root access
Thread Tools
Mac Enthusiast
Join Date: May 2000
Location: Collie-fornya
Status: Offline
Reply With Quote
Nov 26, 2003, 02:04 PM
 
See details here:

Carrel Org Advisory
Suicide Bombers: That never-say-die spirit. No, that's not right.
     
Dedicated MacNNer
Join Date: Jul 2002
Location: Boston, MA
Status: Offline
Reply With Quote
Nov 29, 2003, 11:25 PM
 
Interesting, but I would not scream from the hills about it. There are very specific conditions to meet for this sploit to work (if it is a real threat, as I have not heard anything from a reputable pen-tester.

Exploits are not to be taken lightly, but I doubt the veracity of the claim without further evidence from people like @stake, Symantec, </insert people who don't suck here>



OK, got a notice from Deepsight. Seems the threat is fairly limited. Either your DHCP servers have to be compromised or a rouge DHCP server on your local segment has to be present when you are broadcasting for a DHCP lease. Possible, but unlikely unless one's defenses are pretty lax for critical infrastructure.
(Last edited by kampl; Dec 3, 2003 at 06:19 PM. )
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 02:15 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2