Re: BIG INFORMIX I-SPY SECURITY HOLE
Posted in 2004
Topics: Installation, Setup & Upgrades
"nobody" <nobody@devnull.org> wrote in message news:40D2F588.2000001@devnull.org... > > > Obnoxio The Clown wrote: > > David Williams said: > > > OTC and DW two names from the past... > > >>Install i-spy into /opt/ispy... > >> > [SNIP] > > > >>Welcome to the sos zone..you've been hacked!! > > > > > > Presumably you have reported this to IBM and given them time to fix it? > > > > Most likely not, however, I-SPY itself is a security risk. But thats > another issue... ;-) > > As to the "hacked"... > > 1) You need access to the actual box which means you've already been hacked. > > 2) You need to install I-SPY or have it installed. > > Not a big security hole, but it is a lapse in security none the less. > It is a big hole I could have had root on a box where I am just a developer...I could have changed anything on that box...love to see what could have happened if it had been put on a production box where as a developer I have limited shell access..certainly not root access! > > But hey, what do I know? > Its not like I'm supposed to be technical. ;-) Yep! >
David Williams wrote: > "nobody" <nobody@devnull.org> wrote in message > news:40D2F588.2000001@devnull.org... > >> >>Obnoxio The Clown wrote: >> >>>David Williams said: >>> >> >>OTC and DW two names from the past... >> >> >>>>Install i-spy into /opt/ispy... >>>> >>> >>[SNIP] >> >> >> >>>>Welcome to the sos zone..you've been hacked!! >>> >>> >>>Presumably you have reported this to IBM and given them time to fix it? >>> >> >>Most likely not, however, I-SPY itself is a security risk. But thats >>another issue... ;-) >> >>As to the "hacked"... >> >>1) You need access to the actual box which means you've already been > > hacked. > >>2) You need to install I-SPY or have it installed. >> >>Not a big security hole, but it is a lapse in security none the less. >> > > > It is a big hole I could have had root on a box where I am just a > developer...I could have > changed anything on that box...love to see what could have happened if it > had been put on > a production box where as a developer I have limited shell > access..certainly not root access! > Perhaps you misunderstand. Its a hole, but not a big hole. You first have to have access to the box. There are other holes in the OS that pose more of a risk because you merely need to be able to see the box in order to hit it. Its not a big security risk because if you are running in a secure environment you would have other things that would help protect you from an outside incursion. Anyone still using emacs? There's a couple of potential security issues there. ;-) What you point out is true. If you have access to the box and you're running I-Spy, you have a potential hole. So don't run I-Spy. As I said earlier. I-Spy also poses security risks too, by its very nature. > >>But hey, what do I know? >>Its not like I'm supposed to be technical. ;-) > > > Yep! > Yeah, but I still am. ;-) And the odds are that my outdated knowledge of "hacks" are still valid for a lot of machines. Thats part of my point. If you want to gripe about a security risk take a holistic look. If you want to report a security risk, then call your rep, or PPA, or post a non specific message and wait for an e-mail reply from the lab(s). > >
nobody wrote: > David Williams wrote: >> "nobody" <nobody@devnull.org> wrote: >>> Obnoxio The Clown wrote: >>>> David Williams said: >>>>> Install i-spy into /opt/ispy... >>> [SNIP] >>>>> Welcome to the sos zone..you've been hacked!! >>>> Presumably you have reported this to IBM and given them time >>>> to fix it? No. It would have been nice to have time to at least develop a workaround, which isn't actually all that hard. In fairness, David did copy me on the information when he posted it, as I asked him to, and I didn't formally ask him not to post it until we had a chance to do something about it. But it is common courtesy and normal practice in the more experienced parts of the security community to report the problem privately and wait for a response. A formal response from IBM about this I-Spy problem will be forthcoming. In the interim, the basic workaround is to remove the SUID root privileges from $ISPY_DIR/bin/runbin and put SUID root privileges on $ISPY_DIR/bin/realbin/ispy, but remove public execute permission from it (only informix or root should run the daemon). The more complete workaround will do various other bits to improve the security, but those steps alone largely deal with problem. The solution - a new release of I-Spy - will formalize all those steps and add some other security checking technology like that added to 9.40.UC3 et al. In general, if you find an Informix security problem, please consider reporting it to me at either of my reasonably well-known email addresses (see signature). You get a rapid acknowledgement of the report, usually a rapid confirmation that you're correct with a bug number, and an outline of how we're going to address the issue, and routine updates until everyone is ready to go public on it. >>> Most likely not, however, I-SPY itself is a security risk. But >>> thats another issue... ;-) >>> >>> As to the "hacked"... >>> >>> 1) You need access to the actual box which means you've already been >>> hacked. The attack described is certainly one which requires a local login shell, but anybody with a login shell can execute it. And hacking into a box as an unprivileged user is seldom a major problem -- it should be much harder to get in as a privileged user. >>> 2) You need to install I-SPY or have it installed. >>> >>> Not a big security hole, but it is a lapse in security none the >>> less. Bigger than I like. >> It is a big hole I could have had root on a box where I am just a >> developer...I could have changed anything on that box...love to >> see what could have happened if it had been put on a production >> box where as a developer I have limited shell access..certainly >> not root access! >> > Perhaps you misunderstand. > It's a hole, but not a big hole. That's subjective - it isn't a small security hole. > You first have to have access to the box. There are other holes in > the OS that pose more of a risk because you merely need to be able > to see the box in order to hit it. True. > It's not a big security risk because if you are running in a secure > environment you would have other things that would help protect > you from an outside incursion. > > Anyone still using emacs? There's a couple of potential security > issues there. ;-) > > What you point out is true. If you have access to the box and you're > running I-Spy, you have a potential hole. > > So don't run I-Spy. > > As I said earlier. I-Spy also poses security risks too, by its very > nature. > >>> But hey, what do I know? >>> Its not like I'm supposed to be technical. ;-) >> >> Yep! >> > Yeah, but I still am. ;-) > And the odds are that my outdated knowledge of "hacks" are still > valid for a lot of machines. Thats part of my point. If you want to > gripe about a security risk take a holistic look. > > If you want to report a security risk, then call your rep, or PPA, > or post a non specific message and wait for an e-mail reply from > the lab(s). Or, in the case of Informix products, contact me - as I said earlier. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/