Groups | Blog | Home
all groups > macromedia flash flashcom > december 2004 >

macromedia flash flashcom : urgent - info about flashcom and security holes


ottocid
12/22/2004 10:24:32 AM
Dear Macromedia, my name is Giovanni Gasparri and I work for an italian company
called 2ware Srl as unix-like system manager. We are working on a project for
E.N.E.A. (Italian National Agency for New Technologies, Energy and the
Environment) (http://www.enea.it/com/ingl/default.htm) based on Flash
Communication Server. I've installed FCS successfully on a 4-processors server
running Scientific Linux instead of Red Hat. Any E.N.E.A.'s server uses AFS
(http://www.openafs.org/) as distributed file system. I've put successfully
the FCS web folder into the /afs shared folder. Anything has been working
until few days ago, when we discovered that: - a large amount of sendmail
traffic is generated; - a large amount of processes are instanced; some of them
are ('sleeping') not visible using the ps command but visible under /proc/; -
log files have been deleted; - the server crashed and I had to reinstall any
package. E.N.E.A.'s technicians suspect a root-kit or something similar. Since
those servers hold very confidential scientific data, they are seriously
thinking of isolating any FCS server from their network, to avoid further
damages. Any Flash Communication Server will be removed as soon in the case
I'll receive no formal answer from you about the following questions: - does
Flash Communication Server use the sendmail service? - can the FCS algorithm
instance so many processes? Is this one a normal behavior? - do you know any
FCS vulnerabilities allowing arbitrary code execution? - can some processes of
those one be a malicious process? - can those troubles be solved by make FCS
running on Red Hat instead of Scientific Linux? - can those problems be
connected in such way to FCS? Unfortunately I cannot answer my customers
directly since FCS is not provided under GPL. I'm waiting for an urgent answer
from your experts to avoid E.N.E.A. decides to dismiss FCS ultimately. Thanks
for your kind answer. - - - Giovanni Gasparri Technical Support - 2ware Srl
http://gasparri.2ware.it
ion gion
12/30/2004 10:34:40 PM
Hi Giovanni,

Macromedia doesnt answer to forums, they are too lazy, flash comm server is a
high secret for them, a verry good product but filled wiht no care by them
regarding developers.

I suggest you unload all the applications that are running on your flash comm
server.

Then do not allow anyone to connect to it.

Restart flash comm after unloading all.
Keep it isolated and watch for it if it generates any more traffic.

If so then remove it and download it from macromedia website and then install
it and add your commercial licenses, add also updater2.(in this way you set
aside the thought of a rootkit - i dont think MM will shoot themselfs in their
foot)

Then do an analisys of the applications that run under it, bad developers and
bad designed and programmed applications can cause the server to crash and one
of those can create "many processes" as you mention.

On linux i hear a lot of flame that FCS is bad, verry bad for the linux
platform, i used it and did not experienced a single problem ( as a developer
for intensive applications, on a nonstandard distro - slackware and ubuntu ).

Try to put RedHat, your Scientific Linux might also be the problem.
AddThis Social Bookmark Button