Re: BIG INFORMIX I-SPY SECURITY HOLE
Posted in 2004
"Jonathan Leffler" <jleffler@earthlink.net> wrote in message news:40D91278.3030401@earthlink.net... > nobody wrote: > > David Williams wrote: > >> "nobody" <nobody@devnull.org> wrote: > >>> Obnoxio The Clown wrote: > >>>> David Williams said: > >>>>> Install i-spy into /opt/ispy... > >>> [SNIP] > >>>>> Welcome to the sos zone..you've been hacked!! > >>>> Presumably you have reported this to IBM and given them time > >>>> to fix it? > > No. It would have been nice to have time to at least develop a > workaround, which isn't actually all that hard. In fairness, David did > copy me on the information when he posted it, as I asked him to, and I > didn't formally ask him not to post it until we had a chance to do > something about it. But it is common courtesy and normal practice in > the more experienced parts of the security community to report the > problem privately and wait for a response. > True, but I found it in less than 10 minutes. I assumed anyone with bad intentions would also be able to find it that fast. So if you are vunerable and someone wanted to you've probably already been hacked! Better to stop anyone else installing it! > A formal response from IBM about this I-Spy problem will be > forthcoming. In the interim, the basic workaround is to remove the > SUID root privileges from $ISPY_DIR/bin/runbin and put SUID root > privileges on $ISPY_DIR/bin/realbin/ispy, but remove public execute > permission from it (only informix or root should run the daemon). The > more complete workaround will do various other bits to improve the > security, but those steps alone largely deal with problem. The > solution - a new release of I-Spy - will formalize all those steps and > add some other security checking technology like that added to > 9.40.UC3 et al. > > In general, if you find an Informix security problem, please consider > reporting it to me at either of my reasonably well-known email > addresses (see signature). You get a rapid acknowledgement of the > report, usually a rapid confirmation that you're correct with a bug > number, and an outline of how we're going to address the issue, and > routine updates until everyone is ready to go public on it. OK. What if the problem is as obvious as this? Perhaps better to stop people from installing it?