Re: How to Check the Security of $INFORMIXDIR and
Posted in 2008
Topics: Installation, Setup & Upgrades, Storage & Space Management, Platform-Specific Issues
On Sat, Jul 26, 2008 at 12:32 AM, Jonathan Leffler <jleffler.iiug@gmail.com> wrote: > Some, maybe even many, of you have heard me say "Make sure that > $INFORMIXDIR and all the directories in the path leading to it are > secure" and "Make sure that the paths leading to your chunks are > secure", but how many people are really sure they know when something > is secure and when it is not really secure? > > OK - there was at least one hand moving out there near the back of the > audience - just a little. > > I've uploaded a program to the IIUG Software Archive (hint, hint - O > Keepers of the IIUG Software Archive - and it is the second version, > 2.34, that should be made public, please) called linkpath which is my > current tool for assessing whether a path leading to a file (or a > directory) is really secure. It should compile on just about any > version of Unix or Linux you can lay hands on; I've compiled it on > HP-UX, Solaris 10, Linux, AIX, and MacOS X. > > Usage: linkpath [-adhsvV][-u user][-g group] file [...] > -a Process absolute names > -d Print diagnostic output > -g group Treat user as trusted > -h Print this help message and exit > -s Security check directories > -u user Treat user as trusted > -v Verbose mode > -V Print version and exit > > The program chases down insecure directories - defined as a directory > that is publicly writable, or a directory that is owned by a > non-trusted group that is group writable, or a directory that is owned > by a non-trusted user. It reports on insecure files too. It follows > symlinks, but analyses the path that the symlink traverses to make > sure there are no insecure directories on the way. The trusted users > are root, bin, sys and informix; the trusted groups are bin, sys, > informix, and group 0 (sometimes root, sometimes wheel (MacOS X), > sometimes system (AIX)), and the group that owns the root directory > (admin, 80, on MacOS X; group 0 on other systems). > > I am interested to know (a) if you have any problems compiling it > (platform - o/s and compiler - would be relevant), and (b) whether any > of your INFORMIXDIRs are insecure. One way of checking that is: > > linkpath -sv `cat /INFORMIXTMP/.infxdirs` > > Or - Korn Shell or Bash: > > linkpath -sv $(</INFORMIXTMP/.infxdirs) > > One reason for asking is to find out how much trouble would be caused > if a security check based on this code was added to fix packs of IDS, > with ON-Init in particular not starting unless $INFORMIXDIR was secure > according to the criteria checked by this code. > > [And one reason for asking is because I've been saddened to find that > most of the R&D and QA machines do not pass this security test. > Granted, security isn't a major problem inside IBM's firewalls - but I > was a little surprised at the extent of the problems I have to work > around. > My machine passes muster (funny that!) except for one INFORMIXDIR, > which is the result of a build without a formal install. If the > 'uninstalled build' was the only reason the R&D and QA machines > failed, I'd be happier; sadly, it isn't.] > > -- > Jonathan Leffler #include <disclaimer.h> > Email: jleffler@earthlink.net, jleffler@us.ibm.com > Guardian of DBD::Informix v2008.0513 -- http://dbi.perl.org/ > "Blessed are we who can laugh at ourselves, for we shall never cease > to be amused." > NB: Please do not use this email for correspondence. > I don't necessarily read it every week, even. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > I'm not sure if you prefer to keep this off the list... On my CentOS release 5.2 system I get an error saying 'invalid user 'sys''. Here's the output from linkpath -sdv `cat /INFORMIXTMP/.infxdirs`: root directory: st_dev - 64768, st_ino = 2, st_gid = 0 grp bin => gid 1 grp sys => gid 3 grp informix => gid 344 usr root => uid 0 usr bin => uid 1 usr sys => unknown! linkpath: invalid user 'sys' FYI, I have a group called 'sys' but not user called 'sys' on all my Linux systems: Red Hat Enterprise Linux ES release 4 (Nahant Update 6) CentOS release 5.2 Jim
On Tue, Aug 12, 2008 at 7:03 AM, Jim Tranny <jimtranny@gmail.com> wrote: > On Sat, Jul 26, 2008 at 12:32 AM, Jonathan Leffler > <jleffler.iiug@gmail.com> wrote: >> Some, maybe even many, of you have heard me say "Make sure that >> $INFORMIXDIR and all the directories in the path leading to it are >> secure" and "Make sure that the paths leading to your chunks are >> secure", but how many people are really sure they know when something >> is secure and when it is not really secure? >> >> OK - there was at least one hand moving out there near the back of the >> audience - just a little. >> >> I've uploaded a program to the IIUG Software Archive (hint, hint - O >> Keepers of the IIUG Software Archive - and it is the second version, >> 2.34, that should be made public, please) called linkpath which is my >> current tool for assessing whether a path leading to a file (or a >> directory) is really secure. It should compile on just about any >> version of Unix or Linux you can lay hands on; I've compiled it on >> HP-UX, Solaris 10, Linux, AIX, and MacOS X. >> >> Usage: linkpath [-adhsvV][-u user][-g group] file [...] >> -a Process absolute names >> -d Print diagnostic output >> -g group Treat user as trusted >> -h Print this help message and exit >> -s Security check directories >> -u user Treat user as trusted >> -v Verbose mode >> -V Print version and exit >> >> The program chases down insecure directories - defined as a directory >> that is publicly writable, or a directory that is owned by a >> non-trusted group that is group writable, or a directory that is owned >> by a non-trusted user. It reports on insecure files too. It follows >> symlinks, but analyses the path that the symlink traverses to make >> sure there are no insecure directories on the way. The trusted users >> are root, bin, sys and informix; the trusted groups are bin, sys, >> informix, and group 0 (sometimes root, sometimes wheel (MacOS X), >> sometimes system (AIX)), and the group that owns the root directory >> (admin, 80, on MacOS X; group 0 on other systems). >> >> I am interested to know (a) if you have any problems compiling it >> (platform - o/s and compiler - would be relevant), and (b) whether any >> of your INFORMIXDIRs are insecure. One way of checking that is: >> >> linkpath -sv `cat /INFORMIXTMP/.infxdirs` >> >> Or - Korn Shell or Bash: >> >> linkpath -sv $(</INFORMIXTMP/.infxdirs) >> >> One reason for asking is to find out how much trouble would be caused >> if a security check based on this code was added to fix packs of IDS, >> with ON-Init in particular not starting unless $INFORMIXDIR was secure >> according to the criteria checked by this code. > I'm not sure if you prefer to keep this off the list... No problem at all. It's just a bug in my code -- it happens, despite all the testing I do. > On my CentOS release 5.2 system I get an error saying 'invalid user > 'sys''. Here's the output from linkpath -sdv `cat > /INFORMIXTMP/.infxdirs`: > root directory: st_dev - 64768, st_ino = 2, st_gid = 0 > grp bin => gid 1 > grp sys => gid 3 > grp informix => gid 344 > usr root => uid 0 > usr bin => uid 1 > usr sys => unknown! > linkpath: invalid user 'sys' > > FYI, I have a group called 'sys' but not user called 'sys' on all my > Linux systems: > Red Hat Enterprise Linux ES release 4 (Nahant Update 6) > CentOS release 5.2 Thanks for the information. I had to make a related fix (no user bin or sys on MacOS X) earlier today (as well as another fix to prevent a core dump on Solaris 9 because its bsearch on zero-length lists tries poking around the non-existent data - other platforms all handle that case fine!) and made the equivalent fix in the group handling, even though I didn't know it was needed (mainly to retain as much symmetry as possible). I'll send you the new version directly, Jim, and will upload to the IIUG web site. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2008.0513 -- http://dbi.perl.org/ "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." NB: Please do not use this email for correspondence. I don't necessarily read it every week, even.