Exploit found in Tails Linux 0.16 firewall


Recommended Posts

sourcehttp://cryptome.org/2013/01/tails-exploit.htm

I'm not tech inclined by most means but thought this might be of interest to you techno geeks who are "in the know" I'll quote the important section from the above link

Tails Linux version 0.16 - Firewall Disabling Script Waits For Exploitation

A sends:

Tails Linux version 0.16 - Firewall Disabling Script Waits For Exploitation

"If you?re running Tails version 0.15 or 0.16, please locate and delete the following file each session:

/usr/local/sbin/do_not_ever_run_me

The file, if ran with correct permissions, will completely disable your firewall! So much for the idea that Tails always routes everything through Tor! Where this news has been posted and comments allowed, mysterious ?anonymous? users have expressed their low brow intelligence leaving comments such as, ?Well you need to be root to run it so it doesn?t matter, if you have root you can do anything!?

First of all, a file called ?do_not_ever_run_me? shouldn?t be on a Linux system. If it should NEVER BE RUN, and that means by anyone, root or user, local or remote, it SHOULD NOT BE INCLUDED IN THE DISTRIBUTION!

Any current or future exploit which targets this file will ?drop the shields? for the Tails user.

Perhaps Tails itself in its next version, 0.17, should be nicknamed, ?do_not_ever_run_me?.

Another questionable decision by the Tails developers is to place the following line within the torrc file (located at /etc/tor/torrc):

## We don?t care if applications do their own DNS lookups since our Tor

## enforcement will handle it safely.

WarnUnsafeSocks 0

Oh, really? We don?t care? Who is we? It?s not me! As the man page for Tor states, this is set to 1 by default, yet Tails sets it for 0! So if something ?leaks?, you will never know it? Each session, delete this line or comment it out so the default is 1 like it should be for a Tor session.

What else can we find in this anonymously developed distribution? I?m glad I?m not driving a car with software made by this group of developers."

aka: Tails 0.16 lower shields

src: anonymous

I've never heard of this distribution myself, but the comments from a former developer of the distro adds some notes about this in the linked post, namely about running as root and why the WarnUnsafeSocks is set as it is.

This isn't an exploit in the Linux firewall.

ok maybe not an exploit per se' however, I'm able to wrap my feeble mind around this and deduct that the devs sent a script to disable the firewall. Dunno... :/

If your root you can disable the firewall - so why wouldn't it be scripted out if more than one command. I could see plenty of uses for such a file, troubleshooting issues for example. Pfsense has a checkbox that I can check that turns off the firewall, so is that an exploit??

post-14624-0-44586600-1361127614.png

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Exactly what I was thinking. All of a sudden in span of a month multiple CEO's from scam altman to this clown has had sudden change of heart does not seem organic change lol
    • Microsoft releases Visual Studio Code 1.124 with smarter autonomous AI agents by Paul Hill Microsoft has just released Visual Studio Code 1.124 with a focus on faster agent workflows and improved agent autonomy. Microsoft outlined the following features as the key items in this update: Autopilot: Autopilot, enabled by default, is now smarter to determine when a task is truly done. Background sessions: Quickly send a request in the background and keep composing the next session. Session navigation: Search, jump, and step through agent sessions with the keyboard. Browser history: Revisit and search pages you've already opened in the integrated browser. With VS Code 1.124, Microsoft has enabled Autopilot by default. For those that don’t know, Autopilot is a chat permission level that you can pick to give agents permission to take initiative and act autonomously, without needing explicit user approval for each action. Also related to Autopilot, Microsoft introduced Advanced Autopilot, which changes how Autopilot decides when to keep iterating and when to finish. This helps you get more complete results without manually monitoring loops. This feature works using a small utility model that reads a transcript of the chat and decides when the task is done. Another new feature in 1.124 is the Agents window, which lets you easily explore, iterate on, and review agent sessions across projects and machines. Previously, starting a new agent session meant waiting for it to load before you could compose the next one. With this update, sessions can be requested in the background. This VS Code update also brings session navigation updates to switch between them more quickly. The update also lets you reload or reopen the Agents window so that it no longer loses your layout, so you will land back where you left off. If you use the integrated browser in VS Code, you will notice that it now retains the history of visited pages. Suggestions will now show when typing in the URL bar and can be managed by using Ctrl+H within a browser tab. The browser now also lets you customize the toolbar more; just right-click on the toolbar area to the right of the URL input. Finally, the browser has faster agentic text entry. Another improvement is experimental enterprise-managed Copilot plugin policies that allow admins to centrally control which chat plugins and plugin marketplaces are available to developers. If you have VS Code installed, 1.124 should install automatically, or you'll get a prompt. If you don't have it installed, get it here.
    • Ray-Tracing is the Radeon RX 9070 XT's biggest weakness. The Radeon RX 9070 XT might not be able to match in the GeForce RTX 5070 Ti in ray-tracing, but it can beat the GeForce RTX 5070, which is around the same price.
    • I am also on latest experimental with possible insider flags on and aiming in settings for 26h1.. Also see just this wasted space. I do love "movable" small taskbar though but would love more if it had date next to it now just time.
    • Does not make it more readable for me though. The majority of your screenshot is just pitch black.
  • Recent Achievements

    • First Post
      X-No-file earned a badge
      First Post
    • One Month Later
      johnjacobb40 earned a badge
      One Month Later
    • One Year In
      Primer1st earned a badge
      One Year In
    • Experienced
      JayZJay went up a rank
      Experienced
    • Reacting Well
      Sir_Timbit earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      512
    2. 2
      PsYcHoKiLLa
      220
    3. 3
      +Edouard
      145
    4. 4
      ATLien_0
      87
    5. 5
      Steven P.
      86
  • Tell a friend

    Love Neowin? Tell a friend!