Command Path Security in Go
blog.golang.org
blog.golang.org
Good security tip/reminder! It's a slight inconvenience to have to type "./" in front of any local executable or script you want to run, and it's tempting to add "." to $PATH, but here's a good reason it's not there by default.
If you're using zsh, it has the "command_not_found" option, which will be triggered for shell commands that aren't found, but won't be triggered for subcommands or non-interactive shells.
If you add the following as your command not found handler, you'll be able to keep on typing "a.out" instead of "./a.out" without the security issue.
command_not_found_handler() { [ -x "./$0" ] && exec "./$@" }
Bash has a similar mechanism (command_not_found_handle) as well.Putting "." at the start of PATH is probably not a good idea (and probably also not very convenient), but putting it at the end should be mostly harmless for most desktop users.
The vulnerability this post is about is one where command_not_found is safe, but a '.' at the end might not be (if you don't have 'gcc' installed, but the malicious repository you 'go get' included a 'gcc' executable)
A user's interactive terminal having certain conveniences is different, and the command not found handler is only used in an interactive context.
Yes, if a user types "pwnme" in their terminal in a directory that has a malicious executable from the internet named "pwnme", they're owned. Same as if they type "./pwnme" without the command not found handler.
It doesn't really change anything; you have to be aware of what you're typing and what it'll do at an interactive terminal.
The go one is a vulnerability because 'go get' is supposed to have a contract that it can't execute arbitrary code, while an interactive terminal that a user types text into doesn't necessarily have that contract.
Also, it will try the path _first_ before command-not-found, so most forms of this vulnerability (a file named 'ls' or whatever) won't cause a vulnerability with this helper variant.
The difference between "run a system command" and "run a command in this directory" is as different to me as "the cat" and "a cat" -- I'm as likely to forget the `./` as I am to forget an article when composing a sentence.
On my keyboard I've remapped the caps lock to control, pause/break to suspend, etc. Is "§" used often, or could that be safely remapped?
It’s a miracle that Windows and Unix converged a similar implantation.