Exploit found in Tails Linux 0.16 firewall


Recommended Posts

sourcehttp://cryptome.org/2013/01/tails-exploit.htm

I'm not tech inclined by most means but thought this might be of interest to you techno geeks who are "in the know" I'll quote the important section from the above link

Tails Linux version 0.16 - Firewall Disabling Script Waits For Exploitation

A sends:

Tails Linux version 0.16 - Firewall Disabling Script Waits For Exploitation

"If you?re running Tails version 0.15 or 0.16, please locate and delete the following file each session:

/usr/local/sbin/do_not_ever_run_me

The file, if ran with correct permissions, will completely disable your firewall! So much for the idea that Tails always routes everything through Tor! Where this news has been posted and comments allowed, mysterious ?anonymous? users have expressed their low brow intelligence leaving comments such as, ?Well you need to be root to run it so it doesn?t matter, if you have root you can do anything!?

First of all, a file called ?do_not_ever_run_me? shouldn?t be on a Linux system. If it should NEVER BE RUN, and that means by anyone, root or user, local or remote, it SHOULD NOT BE INCLUDED IN THE DISTRIBUTION!

Any current or future exploit which targets this file will ?drop the shields? for the Tails user.

Perhaps Tails itself in its next version, 0.17, should be nicknamed, ?do_not_ever_run_me?.

Another questionable decision by the Tails developers is to place the following line within the torrc file (located at /etc/tor/torrc):

## We don?t care if applications do their own DNS lookups since our Tor

## enforcement will handle it safely.

WarnUnsafeSocks 0

Oh, really? We don?t care? Who is we? It?s not me! As the man page for Tor states, this is set to 1 by default, yet Tails sets it for 0! So if something ?leaks?, you will never know it? Each session, delete this line or comment it out so the default is 1 like it should be for a Tor session.

What else can we find in this anonymously developed distribution? I?m glad I?m not driving a car with software made by this group of developers."

aka: Tails 0.16 lower shields

src: anonymous

I've never heard of this distribution myself, but the comments from a former developer of the distro adds some notes about this in the linked post, namely about running as root and why the WarnUnsafeSocks is set as it is.

This isn't an exploit in the Linux firewall.

ok maybe not an exploit per se' however, I'm able to wrap my feeble mind around this and deduct that the devs sent a script to disable the firewall. Dunno... :/

If your root you can disable the firewall - so why wouldn't it be scripted out if more than one command. I could see plenty of uses for such a file, troubleshooting issues for example. Pfsense has a checkbox that I can check that turns off the firewall, so is that an exploit??

post-14624-0-44586600-1361127614.png

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The problem isn't with Epic, it's with the platform holders like Steam and Nintendo, they should be a lot more strict in their review process.
    • Hello, Installed here without issue. Regards, Aryeh Goretsky
    • Microsoft updates Visual Studio Code with easier language model discovery and in-app search by Paul Hill Microsoft has released Visual Studio Code 1.125, its latest weekly release. This week, the company has focused on discovering and installing extra language models via the Marketplace; searching the web and securely browsing over remote connections without leaving VS Code; choosing how long VS Code waits before installing extension updates; and delivering managed Copilot settings through existing device management tooling. In older versions of VS Code, extensions could contribute their own model providers, but to find these extensions, you needed the right tags to search for in the Extension view. Now, the Language Models editor gives you an Install Model Providers button that opens the Extensions view, which is filtered to extensions that contribute model providers, making it easier to find and install them. Once you install a provider, its model will appear in the model picker. If you use the integrated browser much, you can now look up information without leaving VS Code by typing a query into the integrated browser’s address bar. It will use your configured search engine, the same way a standalone browser does. You can use workbench.browser.searchEngine to pick a search engine. When the browser is opened in a remote workspace, it's now possible to proxy HTTP(S) traffic via the remote connection. This allows you to connect to any ports or services that can only be accessed from the remote machine. If you read our coverage from two weeks ago about VS Code 1.123, you might have seen that extension updates have a two-hour delay as a safety measure. In this update, Microsoft is giving you the ability to configure the time of the delay. You can find it under extensions.autoUpdateDelay. Finally, with this update, admins can deliver managed GitHub Copilot settings through native device management (MDM) channels on Windows and macOS, in addition to account-based enterprise settings files. Settings delivered via MDM appear as policy-enforced in VS Code and can’t be overridden locally. Future updates will extend the supported policy keys across Copilot surfaces. You can download the update from the Visual Studio Code website now.
    • "it opens up new doors for people who prefer using Edge, but cannot be bothered to configure a Microsoft account" You already have a Microsoft account if you are using Windows 11, because you can't set it up without one.
  • Recent Achievements

    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
    • One Month Later
      Vincian earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      543
    2. 2
      +Edouard
      171
    3. 3
      PsYcHoKiLLa
      84
    4. 4
      ATLien_0
      64
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!