HNHacker News
TopNewBestAskShowJobs

ChALkeR

66 karma · joined December 6, 2015

[ my public key: https://keybase.io/chalker; my proof: https://keybase.io/chalker/sigs/s4pY6mFQ3GplQr1rC_cYRZ_KFHPkjLrJyOgnVgWsuxQ ]
submissionscomments
ChALkeR··on Security researcher found ~0.2% of npm users re-used leaked passwords for npm
The correct figure is 10%.
ChALkeR··on Node.js Buffer knows everything – your traffic, sources, keys and configs
Done: https://news.ycombinator.com/item?id=10909727
ChALkeR··on Let's Fix Node.js Buffer API
I tried hard to cover all the possible question. Please, read the post _carefully_ before asking or proposing anything.
ChALkeR··on OpenSSH: client bug CVE-2016-0777
Note: this actually means that everyone should regenerate all their key-pairs after updating.
ChALkeR··on Node.js Buffer knows everything – your traffic, sources, keys and configs
And no, switching Buffer(number) to be zero-filled will bring more harm now, even from the security point of view. The best course of action imo is to deprecate Buffer(number) whatsoever and replace it with two separate methods. More info here: https://github.com/nodejs/node/issues/4660#issuecomment-1712...

I will make a separate post about that soon enough.

ChALkeR··on Node.js Buffer knows everything – your traffic, sources, keys and configs
This note does not have anything actually new, but I have seen several people who are not aware of that.
ChALkeR··on Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
Looks like it bundles libavformat internally.
ChALkeR··on Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
By the way, mplayer is also affected, even after installing a fixed version of ffmpeg.
ChALkeR··on Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
It does not, that's covered in the original article.
ChALkeR··on Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
But that code that you linked to does not verify that the file is mp4, moreover, mp4Sig call is commented out.
ChALkeR··on Ffmpeg vulnerability allows the attacker to get files from your server or PC
Tell me if I should not have double-posted it here, I will delete one of those posts then.
ChALkeR··on Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
Re-posted as https://news.ycombinator.com/item?id=10895872
ChALkeR··on Ffmpeg vulnerability allows the attacker to get files from your server or PC
Short English description:

ffmpeg vulnerability allows reading local files and sending them over network using a specially crafted video file. This affects not only file conversion (including thumbnail generation), but also any other operations that involve ffmpeg processing your file — for example, ffprobe is affected. This is not remote code execution, the vulnerability is limited to reading local files and sending them over network, but that is already bad enough.

For example, a specially crafted «video» file uploaded to your server by an attacker could read your website config/private keys/etc and send that to the attacker once you try to generate a thumbnail for it or just probe it with ffmpeg.

On a PC, you don't even need to open a file to get affected, just downloading it would be enough in some cases — video files are processed with ffmpeg for filemanager thumbnails (i.e. KDE Dolphin), for search indexers, etc.

That vulnerability is public, has code samples to reproduce and build a malicious file, and is not fixed atm.

The recommended quick fix is to rebuild ffmpeg without network support (--disable-network configure flag).

Original post: http://habrahabr.ru/company/mailru/blog/274855/

The original text is in Russian, use https://translate.yandex.com or https://translate.google.com/ to read it.

ChALkeR··on Ffmpeg vulnerability allows the attacker to get files from your server or PC
Previosly posted as https://news.ycombinator.com/item?id=10893301, but that eneded up in [ask] due to my mistake.
ChALkeR··on Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
https://translate.google.com/translate?sl=ru&tl=en&u=http%3A... will work better, I suppose.
ChALkeR··on Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
Should I post this again with a link so it ends up in the news or not?
ChALkeR··on Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
Hm. Why did this end up in [ask]? Perhaps I made a mistake when posting this =).
ChALkeR··on Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
It's «PC» as in «server»/«PC», not as in «mac»/«PC».
ChALkeR··on Survey of popular Node.js packages reveals credential leaks
It's listed here: https://docs.npmjs.com/misc/developers#keeping-files-out-of-...
ChALkeR··on Survey of popular Node.js packages reveals credential leaks
Sigh… Yet another mention of an automatic tool. I guess that I will update the Q/A section to reflect my opinion on such automatic tools.

Edit: done.

ChALkeR··on Survey of popular Node.js packages reveals credential leaks
https://github.com/npm/npm/releases/tag/v2.14.1

> npm will no longer include .npmrc when packing tarballs.

ChALkeR··on Survey of popular Node.js packages reveals credential leaks
You should not trust automatic tools to do that. They will inevitably be subject to both false negatives and false positives, and will most probably just give you a false sense of security but will not protect you from the actual leak.

You should better review stuff that you publish. That includes commit review, package contents review before publishing them, config files review, logs review before sharing them.

If you have an org — it would better to educate your devs more and make each commit go through an independent review. Also, don't forget about checking package contents.

ChALkeR··on Survey of popular Node.js packages reveals credential leaks
For spelling/grammar — yes.
ChALkeR··on Survey of popular Node.js packages reveals credential leaks
While it was not me who posted this to the Hacker News (so don't blame me for the title here), I can assure you that all mentioned credentials were active at the time when I found them.