They are running the good old php shell of "<%= system(%_REQUEST['cmd']) %>". As root. As a security company.
This entire company is just blowing my mind at the moment. What's next, are they running their services on a notebook in the office?
They are running the good old php shell of "<%= system(%_REQUEST['cmd']) %>". As root. As a security company.
This entire company is just blowing my mind at the moment. What's next, are they running their services on a notebook in the office?
For situations like this where a fiasco just keeps getting worse, each step its own facepalm.
* Asking users to generate private keys on the issuer's server
* Storing those private keys
* Emailing those private keys
* Sending that email completely in the clear
* Running unsanitized user input on their server
* as root
Well, their CEO's linked-in profile doesn't really sound like a security company.
> Email Marketing Digital Marketing Google Analytics Google Webmaster Tools Market Analysis Marketing PPC SEM SEO Sales Security Social Media Marketing Web Analytics Affiliate Marketing Google Adwords Management E-commerce Lead Generation Online Marketing Online Advertising SaaS Marketing Strategy Strategic Partnerships Cloud Computing New Business Development Business Strategy Start-ups Web Development CRM Social Media Product Marketing Solution Selling Strategy Channel Partners Channel Sales Business Alliances Business Development Leadership Social Networking Network Security Hardware Product Management B2B Professional Services GTM Partner Program Development Internet Security Google B2B Marketing Sales Operations
Saying that, that quote sounds way too long to not be BS.
(I expect this post will get 0E0 upvotes)
system('openssl req -config /prod/prod-config.cnf -subj "/CN={$DOMAIN}" ....'
And whoever wrote that function assumed someone else had sanitized DOMAIN.It looks like a lot more understandable of a mistake when framed like that.
PHP's system() manpage: http://php.net/manual/en/function.system.php
[red box]
Warning
When allowing user-supplied data to be passed to this function, use escapeshellarg() or escapeshellcmd() to ensure that users cannot trick the system into executing arbitrary commands.
system(3): http://man7.org/linux/man-pages/man3/system.3.html Any user input that is employed as part of command should be carefully sanitized, to ensure that unexpected shell commands or command options are not executed. Such risks are especially grave when using system() from a privileged program.
This is a canonical mistake that's used as a mistake example in textbooks.system() style functionality -> should be the hard thing to do execv() style functionality() -> should be the easy thing to do
Shower thought: Allow me to globally disable system() in for language x. Aside from the obvious case of just banning these insane system calls, you're protected against surprise vectors in parsers.
Edit: You would presumably mitigate pipe open vulnerabilities too
It's just sad that there is no really good tutorial how to write your own SELinux modules for your own applications. It's easier than it seems and allows some really powerful security measures.
I had a similar thought. My thought was: "HOLY SHIT!"
https://trends.google.com/trends/explore?date=all&q=laptop%2...