导读-- Slackware 7, FreeBSD 3.1, and OpenBSD 2.6默认安装配置的bawX系统,存在一个拒绝服务的安全问题,本地一般用户通过执行下面的脚本程序,将导致X服务崩溃......
漏洞发布时间:2000-04-04
漏 洞 描 述:
Slackware 7, FreeBSD 3.1, and OpenBSD 2.6默认安装配置的bawX系统,存在一个拒绝服务的安全问题,本地一般用户通过执行下面的脚本程序,将导致X服务崩溃。对于Redhat,和其它版本的Linux(如Mandrake,
WinLinux,等等)不起作用。
漏洞检测程序如下:
#!/bin/bash
# Simple Local Denial of Service Exploit Against X
# coded by bansh33 of r00tabega
# www.r00tabega.com 0wnz you
#
# propz to my mommy and daddy cuz they make my drink
my milk
#
# Tested under Slackware 7, FreeBSD 3.1, and OpenBSD
2.6
# The problem lies in the fact that most users use the
default config
# of X. A little configuration to specify your monitor,
settings, etc will
# fix this.
# Does not work with Redhat, or anything based off it
(Mandrake, WinLinux, etc)
# Any user can login and execute this to DoS the bawx.