lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Fri, 11 Jul 2014 11:13:32 +0200 From: Joerg Mertin <smurphy@...sys.org> To: fulldisclosure@...lists.org Subject: Re: [FD] QNAP TS-469U shadow file world readable I can confirm that... QNap SS-839 [/etc] # pwd /etc [/etc] # ls -l shadow lrwxrwxrwx 1 admin administ 13 Aug 15 2013 shadow -> config/shadow [/etc] # ls -l config/shadow -rw-r--r-- 1 admin administ 455 Jun 25 2013 config/shadow That is also the reason that my NAS has no access (actively blocked IP address on firewall to deny access out the world interface). I had notified QNap of that some years back - and as they didn't react, implemented my own countermeasures where one is to disallow access to the Internet. On Friday 11 July 2014 10:55:22 Melchior Limacher wrote: > [cid:image001.png@...F9CF6.9CE624D0] > > [cid:image002.png@...F9CF6.9CE624D0] > > > Cheers -- We are Pentium of Borg. Division is futile. You will be approximated. (seen in someone's .signature) ------------------------------------------------------------------------ Joerg Mertin in Clermont/France Web: http://www.solsys.org PGP: Public Key Server - Get "0x159DC660F946126F" _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists