{"id":82,"date":"2003-06-30T16:37:22","date_gmt":"2003-06-30T09:37:22","guid":{"rendered":""},"modified":"2003-06-30T16:37:22","modified_gmt":"2003-06-30T09:37:22","slug":"dantz-retrospect-client-5-0-540-for-mac-os-x-permission-issues","status":"publish","type":"post","link":"https:\/\/deepquest.code511.com\/blog\/2003\/06\/dantz-retrospect-client-5-0-540-for-mac-os-x-permission-issues\/","title":{"rendered":"Dantz Retrospect Client 5.0.540 for Mac OS X &#8211; permission issues"},"content":{"rendered":"<p>serious problem with default permissions of the Retrospect client software, installed on Jaguar client and server (older versions of OS X may be vulnerable too).<br \/>\nIn addition, previous versions of the Retrospect client installer may be vulnerable as well.  We notified Dantz of this vulnerability a week ago, and have yet to hear from them.<!--more--><\/p>\n<p>DESCRIPTION:<br \/>\nAfter a clean installation we noticed the following permissions were set. <\/p>\n<p>\/Library\/StartupItems\/RetroClient<\/p>\n<p>0 drwxrwxrwx   5 admin  staff   170 Apr 30 10:21 RetroClient<\/p>\n<p>\/Library\/StartupItems\/RetroClient\/ :<\/p>\n<p>total 32<\/p>\n<p>0 drwxrwxrwx  5 admin  staff   170 Dec 11 21:05 .<br \/>\n0 drwxrwxrwx  7 admin  staff   238 Feb 20 17:44 ..<br \/>\n16 -rw-rw-rw-  1 admin  staff  6148 Jun 24  2002 .DS_Store<br \/>\n8 -rwxrwxrwx  1 admin  staff   363 Jul  1  2002 RetroClient<br \/>\n8 -rwxrwxrwx  1 admin  staff   208 Mar  1  2001<br \/>\nStartupParameters.plist<\/p>\n<p>If the \/Library\/StartupItems does not already exist, the Retrospect <\/p>\n<p>client installer creates this directory with 777 permissions. In addition, the client installer assigns permissions of the files and folders to the user that installed the software, rather than to the root user.<\/p>\n<p>KNOWN VULNERABLE VERSIONS:<\/p>\n<p>Dantz Retrospect Client 5.0.540 on Mac OS X 10.2.6<br \/>\n(previous versions of the os and client software may be vulnerable as well)<\/p>\n<p>WORKAROUND*:<br \/>\n&#8211; secure the main \/Library\/StartupItems directory if the <\/p>\n<p>Retrospect client installer created it:<br \/>\n        % sudo chmod 775 \/Library\/StartupItems<\/p>\n<p>&#8211; secure the  \/Library\/StartupItems\/RetroClient directory:<br \/>\n        % sudo chmod 775 \/Library\/StartupItems\/RetroClient<\/p>\n<p>&#8211; secure the RetroClient startup directory<br \/>\n        % sudo chmod 755 \/Library\/StartupItems\/RetroClient\/*<\/p>\n<p>*These steps will not change group ownership, which may be necessary or desired on some systems. These are the steps that we took to secure our machines and are in no way a recommendation by Dantz.<\/p>\n<p>credits: Alan McCarty<\/p>\n","protected":false},"excerpt":{"rendered":"<p>serious problem with default permissions of the Retrospect client software, installed on Jaguar client and server (older versions of OS X may be vulnerable too)<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-82","post","type-post","status-publish","format-standard","hentry","category-security"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4bBYZ-1k","_links":{"self":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/82","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/comments?post=82"}],"version-history":[{"count":0,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/82\/revisions"}],"wp:attachment":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/media?parent=82"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/categories?post=82"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/tags?post=82"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}