NeXT NetInfo _writers Vulnerability
BID:58
Info
NeXT NetInfo _writers Vulnerability
| Bugtraq ID: | 58 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Jan 21 1993 12:00AM |
| Updated: | Jan 21 1993 12:00AM |
| Credit: | |
| Vulnerable: |
NeXT NeXTstep 3.0 NeXT NeXTstep 2.1 NeXT NeXTstep 2.0 NeXT NeXTstep 1.0 a NeXT NeXTstep 1.0 |
| Not Vulnerable: | |
Solution / Fix
NeXT NetInfo _writers Vulnerability
Solution:
To close the vulnerabilities, remove the "_writers" properties from
the "/printers", "/fax_modems", and "/localconfig/screens" directories
in all NetInfo domains on the network, and from all immediate
subdirectories of all "/printers", "/fax_modems", and
"/localconfig/screens" directories. The "_writers" properties may be
removed using any one of the following three methods:
A. As root, use the "niutil" command-line utility. For example, to
remove the "_writers" property from the "/printers" directory:
# /usr/bin/niutil -destroyprop . /printers _writers
B. Alternatively, use the NetInfoManager application: open the
desired domain, open the appropriate directory, select the
"_writers" property, choose the "Delete" command [Cmd-r] from
the "Edit" menu, and save the directory.
C. To assist system administrators in editing their NetInfo
domains, a shell script, "writersfix", is available via
anonymous FTP from next.com (129.18.1.2):
Filename Size Checksum
-------- ---- --------
pub/Misc/Utilities/WritersFix.compressed 5600 25625 6
After transferring this file using BINARY transfer type,
double-click on the file. A "WritersFix" directory will be
created in your file system, containing the script
("writersfix") and some documentation ("WritersFix.rtf").
Consider removing "_writers" from other NetInfo directories as well
(for example, "/locations"), noting the following trade-off between
ease-of-use and security. By removing the "_writers" properties, the
network and the computers on the network become more secure, but a
system administrator's assistance is required where it previously was
not required.
Please refer to the NeXTSTEP Network and System Administration manual
for additional information on "_writers". Note that the
subdirectories of the "/users" directory have "_writers_passwd" set to
the user whose account is described by the directory. This is
essential if users are to be able to change their own passwords, and
this does not compromise system security.
Solution:
To close the vulnerabilities, remove the "_writers" properties from
the "/printers", "/fax_modems", and "/localconfig/screens" directories
in all NetInfo domains on the network, and from all immediate
subdirectories of all "/printers", "/fax_modems", and
"/localconfig/screens" directories. The "_writers" properties may be
removed using any one of the following three methods:
A. As root, use the "niutil" command-line utility. For example, to
remove the "_writers" property from the "/printers" directory:
# /usr/bin/niutil -destroyprop . /printers _writers
B. Alternatively, use the NetInfoManager application: open the
desired domain, open the appropriate directory, select the
"_writers" property, choose the "Delete" command [Cmd-r] from
the "Edit" menu, and save the directory.
C. To assist system administrators in editing their NetInfo
domains, a shell script, "writersfix", is available via
anonymous FTP from next.com (129.18.1.2):
Filename Size Checksum
-------- ---- --------
pub/Misc/Utilities/WritersFix.compressed 5600 25625 6
After transferring this file using BINARY transfer type,
double-click on the file. A "WritersFix" directory will be
created in your file system, containing the script
("writersfix") and some documentation ("WritersFix.rtf").
Consider removing "_writers" from other NetInfo directories as well
(for example, "/locations"), noting the following trade-off between
ease-of-use and security. By removing the "_writers" properties, the
network and the computers on the network become more secure, but a
system administrator's assistance is required where it previously was
not required.
Please refer to the NeXTSTEP Network and System Administration manual
for additional information on "_writers". Note that the
subdirectories of the "/users" directory have "_writers_passwd" set to
the user whose account is described by the directory. This is
essential if users are to be able to change their own passwords, and
this does not compromise system security.
References
NeXT NetInfo _writers Vulnerability
References:
References: