No one expects command execution
0x90909090.blogspot.com
0x90909090.blogspot.com
I mean, is it unexpected if `./my_command --execute-this-right-now=somescript.sh` executes somescript.sh?
In other words, even if it's not obvious, doing this creates a security vulnerability:
tar bla bla ${user input}It does:
irb(main):001:0> gets.tainted?
foo
=> true
You can even set $SAFE to 1 or higher to disallow the use of tainted strings in potentially dangerous commands: freya:~ flgr$ ruby -e '$SAFE = 1; system "tar bla bla #{gets}"'
foo
-e:1:in `system': Insecure operation: -r (SecurityError)
from -e:1:in `<main>'
See http://phrogz.net/programmingruby/taint.html for more information.Yes, it does. E.g:
x = STDIN.gets
puts x.tainted?
y = "hello "+x
puts y.tainted?
z = "foo"
puts z.tainted?
The two first will return "true", and the last will print "false". If you set the safe-level appropriately some methods will be disallowed for x and y above (e.g. eval()), though I would not trust that as comprehensive, but it's a lot better than nothing. && sudo rm -rf /
anyway? Which would render the whole point of the article moot.Just to make sure you are on the same page as the rest of us here: in-band and out-of-band is a way to distinguish sending meta information about the data stream through the same channel as the original data. You need an escape mechanism for that, so control characters and such.
Out-of-band signalling indicates that all meta information about the data stream travels through a different (virtual) circuit, in which case there can never be confusion about whether a given chunk is data or meta info.
tar c -- "$directory_to_tar" echo `somescript.sh`Did you read the manpage of every utility on your computers to know that they won't execute a user supplied program? If you didn't you are up to nasty surprises.
That $HOME trick alone would give privilege escalation to anybody that gets a user-level access to a server of mine. Gota change it.
For those sysadmins, yeah, it's unexpected.
the most determined of attackers will always find a way in.
https://www.gnu.org/software/tar/manual/html_section/tar_46....
> "If the archive file name includes a colon (`:'), then it is assumed to be a file on another machine. If the archive file is `user@host:file', then file is used on the host host. The remote host is accessed using [rsh]."
and
> "If you need to use a file whose name includes a colon, then the remote tape drive behavior can be inhibited by using the `--force-local' option."
On many systems, rsh is aliased to ssh, so if you don't properly sanitize your archive names, GNU tar will make network connections.
Until recently shell-scripts was the way you inited a system. I still have almost 2000 shell scripts on my machine that I didn't write myself.
People got owned during shellshock, which means they did run helper programs, in web-facing applications even.
Complexities that are ready to bite the hand of the unwary at the slightest of chances.
Honesty i think the biggest lie in modern times is the MS/Apple lie that computing can be made so simple that even the proverbial aunt Tillie can do it without reading any sort of manual.
If you give rsync command a source or destination with an unescaped colon, it will read an ENVIRONMENT VARIABLE to figure out a command to run to AUTOMATICALLY CONNECT TO ARBITRARY NETWORK RESOURCES. If you have keys, it will even SKIP PASSWORD ENTRY, and with default Kerberos, it will not only skip password, but make a network connections to a login server:port specified by a DNS ENTRY.
Seriously, who is this guy, and why is this trainwreck #1 on HN?
If your argument was that no programmer should be surprised that you can tell an archive utility to execute an arbitrary script, then you and the author of the post are in complete agreement. The remaining difference is that the article actually does something to fix the problem while you merely hurl an implicit insult at anyone who hasn't seen this type of privilege escalation yet. One of these actions is more constructive than the other.
You and I have vastly different opinions on what constitutes privilege escalation.
The parent post's anger and disgust is misplaced, though. This article is informative at a novice level, and well-written to that level. Not a trainwreck.
The problem is that there is a way for untrusted user input to ever touch a shell in the first place.
Seriously, I challenge you to find a language reference that doesn't decry the use of their version of system(3)---because all that does is run the given command under the user's shell.
It's really aggravating to learn something from an article that is making someone more knowledgeable this angry without explanation.
I'm asking you why you thought the knife would stop cutting things when it hit your hand instead of the loaf of bread.
All that said, between Gmail's spam filter, my avoidance of all things bitcoin, and common sense with passwords (don't ever re-use them), most of the damage caused by this doesn't affect me.
I will note, however, that this are why "when you hit return in the URL bar, what actually happens," is a valid interview question, in the same unfortunate sense that FizzBuzz is a valid interview question.
UNIX got battle-hardened during its college years, the cases of unexpected execution are few and far between. One of them is post-install, never run dpkg -i unless you trust the packager.
Is that when it finally gave up making shar archives?
For the unitiated: A shar is a "shell archive", or a shell script which (typically) makes heavy use of 'here documents' to do what tarballs do, only they're shell scripts so you have to execute them and then they can potentially execute arbitrary code unless you read through them very closely and actually understand them.
Yes, people actually made these. Yes, people actually ran these. Yes, they still exist on some old archive FTP servers and so on.
It's amazing how clever you can be when you don't think you'll ever have to care about security or The Sufficiently Stupid User (because sufficiently advanced stupidity is indistinguishable from malice).
telnet somehost someport | sh
(I remember an IRC client installer script hosted on sci.dixie.edu like that.)
Unfortunately we still have
curl http://somehost/somepath | bash
which is not very safe even if somehost is not malicious.
But it was kind of awesome when the Internet was friendly!
In general, all the hype about not executing stuff from the web has a point but is largely confused about where the risks are and aren't (e.g. the "don't pipe wget into the shell" meme).
Look, it's all about trust management. If you trust everyone's good will, like in an academic community, it's fine. If not, you need to manage trust. There are three models for it AFAIK: initial trust, as in SSH; trust to the authorities, as in X.509; and the web of trust, as in PGP/GPG.
They all have their use cases. I like the opportunity to choose.
> …only they're shell scripts so you have to execute them and then they can potentially execute arbitrary code unless you read through them very closely and actually understand them.
> Yes, people actually made these. Yes, people actually ran these.
Running something you downloaded is how every installer works. Self extracting zips are still a thing, too. At least with shars you could read the source.
Oh yeah, even today people still do `curl http://example.com | bash` (If someone were truly evil they'd make the first download from an IP clean and inject bad code into the second. That would catch all the people who `curl | less` first and then run it again piped to bash). :-)
"shar" files existed because "tar" wasn't particularly standardized. As late as 1990, SGI Irix "tar" did bytes in reverse order from SunOS "tar". You had to convert bytes to untar a SunOS archive on Irix.
Are many people security-conscious enough to do the former but security-unconscious enough to do the latter? I would assume that one would do `curl http://example.com > evilscript; vim evilscript` and then `bash evilscript` if necessary.
I wonder why.
a) 70s culture was a brief moment where geek culture was also pop culture, e.g. Monty Python. So geeks will forever adore that moment
b) mass culture underwent a big shift when TV emerged, so that people after TV cannot easily understand culture before TV
c) the disillusionment and paranoia of the 70s is especially relevant today
I don't know, Hawkeye Pierce did a pretty good impression of Groucho Marx.
I think it's down to numbers: There are a Hell of a lot more people born who know about the 1970s alive now compared to people who knew about the 1930s alive in the 1970s. It was a Baby Boom, after all.
I find it unremarkable that people today quote SW.
Can you even think of a MB quote without looking one up? If I made a pun on one, would you recognize it?
If people still do quote Monty Python, I think it's a culty minority or people who study media. The same status as the Marx Brothers and other comedians of bygone eras.
But we can agree to disagree :)
spanish inquisition was flying circus, not holy grail
but my theory is that the vcr, and now the internet, has a lot to do with it, just like you'd expect references to books to increase with the printing press and general increase of literacy
In the past there were also various implementations of a "restricted shell"; it's conceivable that some of these could bypass a restricted shell's restrictions, depending on how they were implemented.
They had an x86 box running RHEL as their firewall/router and I was hired to resolve an (IPSec) issue they were having. I asked for a capture of some specific traffic but their I.T. guys (small company w/ only two technical staff) weren't "fluent" with bpf filters, so they created a user account for me, provided me with access via SSH, and granted me the ability to run tcpdump via sudo.
From the example given, I could have used the "-z" flag to run arbitrary commands and escalate to root (although, in this case, I likely could have gained root simply by asking nicely).
(Sadly command-line programs have yet to pass the threshold of even having a types system at all.)
Seriously, MS doesn't do everything great, but Powershell has typed pipes (typed everything, actually, it's not just stringly like *sh) which are seriously awesome.
The NOS/VE shell had string types and integer types at least. The experience was absolutely horrible. It's hard for me to remember much other than the difficulty of getting anything practical to work, and that may be a consequence of CDC's incredibly poor design choices for the "shell" rather than the types. But I personally have never said "Oh, for a type system in this darn shell!" since then.
Quick! Everyone! Run in circles!
/s
WOW! I better get on going writing my blog post "executing abitrary code with 'date'".