Feb 09,2010
When is a 0day not a 0day? Samba symlink bad default config, (Tue, Feb 9th)
When is a 0day not a 0day? When the exploit ends up being just a poor default configuration issue. It can lead to files being read, that the user has permission to read. Like /etc/passwd for example. The solution? Set wide links = no in the section of your smb.conf and restart smbd to eliminate this problem, from the Samba Symlink Attack posting here. Thanks Elazar! Cheers, Adrien de Beaupr EWA-Canada.com

Twitter
RSS