OPERATING SYSTEM HOLES
AIX
03/06/91 ADVISORY: Possible security problem with rexd
10/17/91 ADVISORY: tftp daemon problem on RS/6000's, CA 91:19
03/19/92 ADVISORY: Local users can run unauthorized commands with uucp & become root
03/31/92 ADVISORY: Vulnerability in passwd on AIX 3.2 and 2007 update of AIX 3.1, CA-92-07
04/27/92 ADVISORY: Anonymous FTP problem in all versions of AIX, CA-92-09
1993 TIP: Kill X-windows server with ctrl-alt-bkspce and obtain a shell
1994 HACK: Root access obtained with: tprof -x /bin/sh
1994 HACK: Race condition in tprof gets root shell
02/24/94 ADVISORY: AIX Performance Tools allows root access
05/23/94 HACK: Obtain root shell with login "-f" flag, CA 94:09
05/26/94 HACK: Users can obtain root shell through environment & crontab entries, CA 92:10
06/02/94 ADVISORY: Remote users can run bsh queue commands at an elevated privilege
04/26/95 HACK: Mount a directory onto a directory of a file onto a file
CISCO
12/10/92 ADVISORY: Access list vulnerability, CA 92:20
04/22/93 ADVISORY: Cisco routers passing source routed packets, CA 93:07
DOS
07/20/94 HACK: Send commands to DOS computers running ANSI.SYS
1995 HACK: How do I defeat a BIOS password?
08/16/95 HACK: How can I reboot the computer from the command line?
08/24/95 HACK: How to decrypt AMI BIOS passwords
HP-UX
01/13/93 ADVISORY: ypbind accepts bogus ypset requests; all users can become root
1994 HACK: Create a file anywhere on a local file system with expreserve
02/07/94 ADVISORY: Users can increase their privileges with subnetconfig
05/18/94 ADVISORY: Local users can obtain root with HP Vue 3.0
02/06/95 ADVISORY: Users can increase access privileges with HP Remote Watch
02/14/95 HACK: NCSA "httpd" 1.3 can be tricked into executing shell commands
02/23/95 ADVISORY: at and cron can be used to gain unauthorized access privileges
05/04/95 ADVISORY: Preparing an HP-UX system against SATAN
06/**/95 HACK: Programmable hpterms "soft-keys" can be used to gain access
LINUX
07/17/95 TIP: Users can remove the passwd file via a bug in lpr
07/05/95 HACK: Exploit SITE EXEC backdoor in wu.ftpd & obtain a root shell
07/11/95 HACK: Kill any Linux process regardless of ownership
09/07/95 HACK: Login as root on Linux systems running NIS
NOVELL
12/14/90 HACK: Brute force password guessers
10/06/92 HACK: KNOCK.EXE lets you become other users
1993 HACK: HACK.EXE gives SuperVisor rights when SuperVisor is logged in
1994 HACK: Crash the Novell file server through the printserver
11/17/95 ADISORY: A Novell 4.x user's name and password may be compromised
--/--/-- Spoof as a Novell 3.x or 2.x server with a trojan LOGIN.EXE
--/--/-- Novell 3.x passwords in clear
--/--/-- Printserver attacks
--/--/-- Netware 4.x volumes accesed with NT and OS/2 clients
--/--/-- How to recover System Admin password with physical access to server
SCO
01/07/92 HACK: The sadc program runs euid root and can create files anywhere [8lgm]
02/10/92 TIP: "at" runs sgid cron, but handles privileges as if running euid 0 [8lgm]
05/24/93 ADVISORY: Legitimate users can be denied the ability to log onto the system, CA 93:08
11/17/93 ADVISORY: Accounts "dos" & "asg" have /tmp and /usr/tmp as home directories, CA 93:13
04/15/94 TIP: Any user can exploit a login bug and become root [8lgm]
10/12/94 TIP: Use prwarn to create files as group "auth" and become root [8lgm]
SGI
10/31/90 ADVISORY: IRIX 3.3 and 3.3.1 has a vulnerability in /usr/sbin/Mail, CA-90:08
03/06/91 ADVISORY: Users can see the output of other user's terminal activity
08/26/91 ADVISORY: Problem with mail in all versions prior to 4.0, CA 91:14
04/10/92 ADVISORY: Problem with lpr in all versions prior to IRIX 4.0.5, CA 92:08
09/25/93 ADVISORY: Accounts w/o passwords & xhost defaults may allow root access
05/19/94 ADVISORY: The BSD print subsystem, "lpr" can create or overwrite any file
08/10/94 TIP: There may be a problem with "serial_ports"
08/11/94 ADVISORY: A user can obtain a root shell through the Help subsystem, CA 94:13
03/07/95 HACK: "colorview" is suid root and can read any file
03/08/95 HACK: If permissions tool is suid/sgid root, any file can be modified
SUN 4.x.x
04/11/89 HACK: Use the -n argument of "login" to gain a root shell
07/26/89 ADVISORY: Vulnerability in SunOS 4.0.* restore(8) command, CA-89:02
08/14/90 HACK: Very old selection_svc exploit, CA-90:05
03/26/91 ADVISORY: Problem with in.telnetd on SunOS 4.1 and 4.1.1, CA 91:02
09/12/91 HACK: "lpr" can be used to remove any file
09/18/91 HACK: Exploit floating point problems in SunOS 4.1.1
01/**/92 HACK: Exploit a race condition in /bin/mail to become root [8lgm]
02/04/92 HACK: Users can exploit the race condition fix for /bin/mail [8lgm]
02/03/93 ADVISORY: Default permissions may allow local users to gain "root" access
12/14/93 HACK: Exploit "loadmodule" with an IFS attack to get a root shell, CA 93:18
1994 HACK: Any user with access to "passwd" can become root [8lgm]
03/02/94 ADVISORY: Rdist problem in all versions up to 4.1.3, CA 94:04
05/27/94 HACK: Use monitor on console to poke holes in memory & obtain root
01/02/95 HACK: Exploit the patched "loadmodule" with a path attack [8lgm]
SOLARIS 2.x
07/01/93 ADVISORY: "vi" and "ex" can be tricked to overwrite any file
12/16/93 ADVISORY: If "fsck" fails during boot, a root shell is run on the console
1994 TIP: Various Solaris2.3, file permission problems
02/11/95 TIP: "bsmconv" may allow root access
05/05/95 HACK: Use "automountd" to mount a floppy with suid programs
08/14/95 HACK: Obtain a root shell from a race condition in "ps", CA 95:09
SUN & SOLARIS
06/11/93 ADVISORY: Versions to Sun 4.1.3 and Solaris 2.2 have hole in expreserve, CA 93:09
1994 TIP: /usr/kvm/crash allows you to browse through kernel kvm
01/16/94 HACK: Spoof the "in.comsat" daemon to read any file, CA 94:06
04/07/95 ADVISORY: Preparing SunOS machines for Satan
VAX
08/24/92 ADVISORY: Users can increase priveleges from the "MONITOR" utility
10/25/90 ANALYZE/PROCESS_DUMP; VMS versions 4.0 through 5.4; CA-90-07
**/**/** Default user accounts left enabled
WINDOWS
03/10/94 ADVISORY: The "cc:Mail" email program writes passwords onto the hard disk
1995 TIP: Sharing files & using TCP/IP may let anyone read from the disk
03/10/95 HACK: Boot a Win NT system with a Linux boot floppy disk to access the NTFS
**/**/** Embedded trojan horses in DLL OR OLE dependat applications
**/**/** Bypassing Win 95, Win 3.1 or Win NT password
ULTRIX
08/14/91 ADVISORY: Vulnerability in Ultrix 4.1 and 4.2 LAT/Telnet, CA 91:11
08/23/91 ADVISORY: Vulnerability in /usr/bin/mail on Ultrix 4.2, CA 91:13