LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris
User Name
Password
Solaris / OpenSolaris This forum is for the discussion of Solaris, OpenSolaris, OpenIndiana, and illumos.
General Sun, SunOS and Sparc related questions also go here. Any Solaris fork or distribution is welcome.

Notices


Reply
  Search this Thread
Old 06-14-2010, 01:47 AM   #1
romeo_tango
Member
 
Registered: Nov 2006
Distribution: Mint
Posts: 148

Rep: Reputation: 15
Adobe Jrun Issue - Solaris 10


Hi,

I have a server running SPARC 64 bit and Solaris 10. One of my client's security team found this issue :

Code:
HTTP_JRun_Double_Slash
Description :

Macromedia JRun could allow a remote attacker to bypass authentication and gain access to the Web administration interface. A remote attacker could send a specially-crafted URL request to the Web

Administration interface appended with an extra forward-slash character to bypass authentication and gain unauthorized access to administrative functions

How to remove this vulnerability

Apply the appropriate patch for your system, as listed in Macromedia Product Security Bulletin MPSB02-06. See References.
I don't understand what does that mean. Does it means I should patch the Jrun in my Solaris box? I looked for jrun in my servers and found no 'jrun' to be patched.

Did I misunderstood something here?

Please help.
Thanks.
 
Old 06-15-2010, 12:42 AM   #2
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
Ouch, it's an eight years old security patch ...

Everything you want to know is probably written here:

http://www.adobe.com/devnet/security...mpsb02-06.html

You should also make sure there are no newer security patch that might apply.
 
Old 06-15-2010, 11:31 PM   #3
romeo_tango
Member
 
Registered: Nov 2006
Distribution: Mint
Posts: 148

Original Poster
Rep: Reputation: 15
Hi Sir,

Yes it is very old one that none of my friends know about it. The problem for me is that we don't use JRun in our server at all. What should I patch if there are no JRun in the server?

If I checked the suspected hacking attempt URLs. it were like these lines :

Code:
http://www.[mywebsite].com//www.[mywebsite].comhttp//www.[mywebsite].comhttp//imcservices.adultfriendfinder.com/p/imc/imc_data.cgi
http://www.[mywebsite].com//www.[mywebsite].comhttp//imcservices.adultfriendfinder.com/p/imc/imc_data.cgi
http://www.[mywebsite].com//imcservices.adultfriendfinder.com/p/imc/imc_data.cgi

note: replace mywebsite with a valid URL of course.
My analysis is that the user's work station was infected by some kind of trojan or virus so that he accessed that [mywebsite] URLs constantly in every 5 minutes interval. Does that possible?

If that's the case then perhaps the firewall alert was only false alarm because I really don't see any hacking attempt in the URLs.
 
Old 06-16-2010, 01:05 AM   #4
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
How do you assert no JRun is installed on this server ?
 
Old 06-16-2010, 01:23 AM   #5
romeo_tango
Member
 
Registered: Nov 2006
Distribution: Mint
Posts: 148

Original Poster
Rep: Reputation: 15
Code:
# ps -aelf | grep jrun
 0 S     root 18838 18823   0  67 20        ?    153        ? 13:18:45 pts/2       0:00 grep jrun
# ps -aelf | grep JRun
 0 R     root 18840 18823   0  87 20        ?     28          13:18:47 pts/2       0:00 grep JRun
# find / -name \*jrun*
# ls -alh /usr/local/apache2/modules/ | grep jrun
I ensured that there was no jrun in the system by above commands. Did I miss something?

Thanks.
 
Old 06-16-2010, 06:55 AM   #6
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
I would have used that command:
Code:
find / -name "*[Jj][Rr][Un]*"
 
Old 06-16-2010, 09:16 PM   #7
romeo_tango
Member
 
Registered: Nov 2006
Distribution: Mint
Posts: 148

Original Poster
Rep: Reputation: 15
Ah I actually already did something like that trying to find JRUN, JRun, Jrun, jrun all of the possibilities but the result is none.

So this means there is no jrun in the system right?
 
Old 06-17-2010, 01:05 AM   #8
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
I'm not familiar with JRun but I would expect some files with JRun in their names to show up. Why not asking your client's security team what made him think JRun was installed ?
 
Old 06-17-2010, 01:37 AM   #9
romeo_tango
Member
 
Registered: Nov 2006
Distribution: Mint
Posts: 148

Original Poster
Rep: Reputation: 15
I already mention why did the JRun issue showed up in 3rd post.
Their firewall detect the false URL as hacking attempts while the URLs were looked like a trojan-caused to me.

I also found that if you have Jrun installed, you will have the JRUN's variable in your environment.
I checked them all and pretty sure now that the server don't have any Jrun in it.

So I guess I'm just gonna close the thread.
Thanks a lot for you help Sir.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Connecting apache and jrun bittus Linux - Software 0 06-10-2010 11:29 PM
Mozilla - Adobe Reader interface issue... Dox Systems - Brian Solaris / OpenSolaris 3 12-13-2007 09:34 AM
LXer: Critical vulnerabilities announced for all Adobe Flash platforms, including Linux and Solaris LXer Syndicated Linux News 0 07-13-2007 11:16 AM
Adobe and FC6 issue tmick Fedora 5 02-25-2007 09:31 AM
Problem monitoring JRun 4 processes via inittab (respawning too fast) - RHEL3 U4 jdaniels73 Linux - Software 3 08-09-2006 08:37 AM

LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris

All times are GMT -5. The time now is 12:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration