SpyderByte.com: OpenVMS.org dba.OpenVMS.org dcl.OpenVMS.org de.OpenVMS.org fr.OpenVMS.org it.OpenVMS.org
   
Home Contribute News, Jobs, Press Releases, etc. Advertise on OpenVMS.org About/Contact Search News Archives
More Links
Printer friendly version
Share this story

Navigation
VMS Audio Network (VAN)
Featured Articles
Vendors
Training
Golden Eggs
Golden Eggs x86
Help for VMS Beginners
Documentation
Developer Resources
Books
Commercial Software
Open Source & Freeware
OpenSource ported to VMS
Resources
FAQs/How-to
Lists/Newsgroups/Forums
Security Advisories & Info
OpenVMS Patches

Forums
 HP ITRC OpenVMS forum
 OpenVMS Hobbyist forums
 Usenet: comp.os.vms

Mailing Lists
OpenVMS.org Newsletter
OpenVMS.org Alerts
Rdb Managers

Roadmaps
OpenVMS Roadmap (2009)
Itanium Roadmap
HP Roadmaps (2002)
BCS Roadmap FAQ (2002)
Storage Roadmap FAQ (2002)


OpenVMS.org Info
OpenVMS.org Admin Staff:
Ken Farmer, Ian Miller
About
Search OpenVMS.org
News Archives
Mobile Edition
Submit News
Advertising Information

OpenVMS.org Websites

Databases running on OpenVMS


Digital Command Languauge


French



German


Italian



Latest News

A summary of recently disclosed OpenVMS Security vulnerabilties
Posted by Ian on Saturday August 23 2008 @ 03:59PM EDT
During the DEFCON16 hacker conference in early August this year there was a presentation on Hacking OpenVMS. Presentations about OpenVMS have not been seen at hacker conferences for many years. In the presentation security researchers from signedness.org presented two security vulnerabilities of the OpenVMS Platform.

Around the same time as DEFCON16 a report was released on the bugtraq distribution list (http://seclists.org/bugtraq/2008/Aug/0056.html) describing a vulnerability which allows remote escalation of privileges with the Finger daemon with Multinet. Process Software Inc has released a patch for Multinet which fixes this problem. However, best practice for publically accessible systems is to disable the Finger client and server.

The presentation at DEFCON16 described two vulnerabilities and generally discussed hacking OpenVMS.

One is a local exploit using a remote (and malicious) Plan File to escalate privileges within the Finger client. Multiple versions of the HP TCP/IP Services for OpenVMS Finger client are vulnerable. No patch is available for this issue. Other vulnerabilities are known in the Finger software. The recommendation is to disable the Finger client and server, as any sensible system manager would do.

The second is a stack corruption vulnerability within a widely used system run-time library routine which can be exploited when that routine is being used in a program installed with privileges. The exploit would typically be used to execute code supplied by the hacker as part of the attack. A successful attack using this mechanism could allow a local unprivileged user to gain privileged access to the system. HP have released a patch for currently supported versions of OpenVMS which fixes this vulnerability (SMGRTL-V0100), however the issue does exist in other versions of OpenVMS. Versions for which the fix has been released are: OpenVMS Alpha V8.3, V8.2, V7.3-2, and OpenVMS Itanium V8.3, V8.3-1H1, V8.2-1

The security researchers have said they had no previous knowledge of OpenVMS and used the usual techniques that they use on other platforms to search for vulnerabilities (eg: techniques such as "stack smashing"). They informed HP of the details of the vulnerabilities weeks before the presentation and no detailed exploits have been released publicly.

The DEFCON16 presentation is now available on the internet and the vulnerabilities have been extensively discussed on the OpenVMS newsgroup (comp.os.vms). The class of vulnerability found has been known on other platforms for a long time. OpenVMS has not been targeted by security researchers for many years but now more probing of OpenVMS security should now be expected. OpenVMS is significantly different to more widely known operating systems and was designed from the beginning to be robust and secure. However flaws in native software or in software ported from other platforms can still open security holes. Proper management of OpenVMS systems will always reduce the risk. OpenVMS remains one of the least vulnerable operating systems in existence.

< SAS and HP OpenVMS Integrity Servers webinar | The latest libPNG library 1.2.31 is available for OpenVMS >



ADVERTISEMENT:
Sponsors







The OpenVMS Consultant
OpenVMS Consulting


The Minimum You Need to Know book series
Books by Roland Hughes


Alpha and VAX Replacement
StanQ.com



Interested in Advertising? Click here...

Friends of VMS
Connect (HP User Community):
Connect Home
Connect Chapters
Connect Special Interest Groups

United Kingdom
Canada
Encompasserve/DECUServe
OpenVMS Hobbyist
More usergroups...
Other Sites:
Aaron's OpenVMS blog
Alexey Chupahin
Arne Vajhoej
DECUS Library Compendium
DJE Systems
Dr OpenVMS blog
Francesco Gennai
Eight-Cubed blog
Free OpenVMS Software
Galen Tackett
HoffmanLabs
Hunter Goatley
Ian Miller
Itanium Solutions Alliance
Jeff Cameron
John Fisher
Syltrem VMS Page (French)
Kednos PL/I
Keith Parris
Migration Specialties
Noetic Systems, Inc
OpenOffice Port to VMS
OpenVMSPlanet.org
OpenVMS Rocks
Preatorian.net
Retrobeep
Steven M. Schweda
SYSMGR Blog
TMESIS Software
Trends That Matter
VAMP (VMS, Apache, MySQL, PHP)
VIM
Vaxination
Visio Cafe (HP Templates)
VMSresource.org.uk
XDelta
Free VMS Accounts:
Deathrow Public OpenVMS Cluster
Encompasserve/DECUServe/EISNER
Polarhome
Fafner
Poetry Hacklab
Marway.Org
In Memory:
John Wisniewski Memorial Site
Terry Shannon Memorial Site


OpenVMS Rings

OpenVMS Webring

Prev

Random

Next

Prev5

List

Next5

OpenVMS Gurus

Prev

Random

Next

Prev5

List

Next5




Home About & Contact Search Archive Mobile Submit News Sponsorship & Advertising
     Copyright © 2001-2007 SCORSE, LLC
OpenVMS® is a trademark of HP
All other trademarks are those of their owners.
    
  SpyderByte.com ;Technical Portals