Exploit found in Tails Linux 0.16 firewall


Recommended Posts

sourcehttp://cryptome.org/2013/01/tails-exploit.htm

I'm not tech inclined by most means but thought this might be of interest to you techno geeks who are "in the know" I'll quote the important section from the above link

Tails Linux version 0.16 - Firewall Disabling Script Waits For Exploitation

A sends:

Tails Linux version 0.16 - Firewall Disabling Script Waits For Exploitation

"If you?re running Tails version 0.15 or 0.16, please locate and delete the following file each session:

/usr/local/sbin/do_not_ever_run_me

The file, if ran with correct permissions, will completely disable your firewall! So much for the idea that Tails always routes everything through Tor! Where this news has been posted and comments allowed, mysterious ?anonymous? users have expressed their low brow intelligence leaving comments such as, ?Well you need to be root to run it so it doesn?t matter, if you have root you can do anything!?

First of all, a file called ?do_not_ever_run_me? shouldn?t be on a Linux system. If it should NEVER BE RUN, and that means by anyone, root or user, local or remote, it SHOULD NOT BE INCLUDED IN THE DISTRIBUTION!

Any current or future exploit which targets this file will ?drop the shields? for the Tails user.

Perhaps Tails itself in its next version, 0.17, should be nicknamed, ?do_not_ever_run_me?.

Another questionable decision by the Tails developers is to place the following line within the torrc file (located at /etc/tor/torrc):

## We don?t care if applications do their own DNS lookups since our Tor

## enforcement will handle it safely.

WarnUnsafeSocks 0

Oh, really? We don?t care? Who is we? It?s not me! As the man page for Tor states, this is set to 1 by default, yet Tails sets it for 0! So if something ?leaks?, you will never know it? Each session, delete this line or comment it out so the default is 1 like it should be for a Tor session.

What else can we find in this anonymously developed distribution? I?m glad I?m not driving a car with software made by this group of developers."

aka: Tails 0.16 lower shields

src: anonymous

I've never heard of this distribution myself, but the comments from a former developer of the distro adds some notes about this in the linked post, namely about running as root and why the WarnUnsafeSocks is set as it is.

This isn't an exploit in the Linux firewall.

ok maybe not an exploit per se' however, I'm able to wrap my feeble mind around this and deduct that the devs sent a script to disable the firewall. Dunno... :/

If your root you can disable the firewall - so why wouldn't it be scripted out if more than one command. I could see plenty of uses for such a file, troubleshooting issues for example. Pfsense has a checkbox that I can check that turns off the firewall, so is that an exploit??

post-14624-0-44586600-1361127614.png

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Although AI is great and has it's use cases they likely have massively overhyped it and it has not delivered as per their expectations. I fully expect them to start saying the same things again when it does get to a certain level of intelligence!
    • Microsoft wants to end printer driver headaches with Windows Ready Print by Usama Jawad A few days ago, Microsoft released Windows 11 Experimental build 26300.8553, bringing a ton of enhancements such as Start menu customization, search improvements, Taskbar polish, and other minor UI tweaks. Another relatively major enhancement snuck deep within the change log was related to upgrades to the Windows printing experience. Now, Microsoft has shared more details about these benefits. For starters, Microsoft has renamed its Modern Print Platform to Windows Ready Print. The company believes that this name highlights its shift in strategy, which now focuses on modernizing, securing, and streamlining the printing experience for Windows devices. Some of the upgrades present in Windows Ready Print have already been seeded to customers and partners. This includes ending support for third-party printer drivers via Windows Update and transitioning towards the Internet Printing Protocol (IPP) and the native Windows IPP printer driver. In line with these changes, new printer installations will default to Windows Ready Print on eligible devices starting from July 2026. However, Microsoft recognizes that not all environments will be able to migrate to this platform immediately, so it will allow users to choose between installing the printer via Windows Ready Print or the traditional OEM process. Users will be able to toggle this configuration through Settings > Bluetooth & Devices > Printers & Scanners > Printer preferences. This control applies only to new printer installations, and its functionality can also be modified via Group Policy as follows: Launch Group Policy Editor Navigate to Local Computer Policy -> Administrative Templates -> Printers Find and select 'Configure Windows Ready Print driver ranking' -> double click to open it Select 'Enabled' (if you wish to enable Windows Ready Print driver selection) or 'Disabled' (if you wish to explicitly disable Windows Ready Print driver selection). Select Apply Select OK Similarly, if you set up Windows protected print mode through the same setting in Windows 11, it will also default to using Windows Ready Print exclusively. Microsoft hopes that these improvements will help eradicate dependency on OEM-specific driver installation processes and simplify printer installations. We'll likely find out more about other tangible benefits in the coming months.
    • Hey what's about the proton vpn firefox extension ? It's not working today
    • On what though? Not Ray Tracing.
  • Recent Achievements

    • One Year In
      Primer1st earned a badge
      One Year In
    • Experienced
      JayZJay went up a rank
      Experienced
    • Reacting Well
      Sir_Timbit earned a badge
      Reacting Well
    • Week One Done
      rubentuben8 earned a badge
      Week One Done
    • Week One Done
      ARaclen earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      PsYcHoKiLLa
      229
    3. 3
      Edouard
      137
    4. 4
      ATLien_0
      87
    5. 5
      Steven P.
      81
  • Tell a friend

    Love Neowin? Tell a friend!