5 ms·
Summary: The author of the article has a web app that allows you to administer programming tests to job applicants. The two languages currently supported are C
by jseifer 16y ago
Summary: The author of the article has a web app that allows you to administer programming tests to job applicants. The two languages currently supported are C and C++. As part of that process, (I'm guessing) the code needs to go through some sort of compilation process.
The author of the article had left a default whitelist on the production box that whitelisted /dev/random as being readable. The attacker compiled a program (took a test I'm guessing) that included /dev/random. The author found out based on ip and sheer luck that the attacker was a user of the system that he had corresponded with previously.
The reason I summarized this is because I wasn't totally clear on what codeboff.in was from the article. It makes sense how an attack like this could happen. The author seems to really know his stuff and the attack vector really was a small oversight. It's pretty unsettling to me, though, how persistent/insane this attacker seems.
- kranner 16y agoThank you, that's a perfect summary.
- RBerenguel 16y agoPerfect, indeed. And sure, the read was disturbing.
- ax0n 16y agoFrom the perspective of an information security researcher with plenty of time spent working on both sides of the issue, I can tell you that any attacker worth their salt will be persistent and use multiple attack vectors to get what they want. This holds true for bored teens, corporate spies and real penetration testers (not just dorks that get paid to run scanning tools on your network) alike. I've spent the last decade doing mostly IT Security defense work. I don't worry when I see someone port-scan my servers. Those kiddos are almost always benign. I worry when I see that our IDS starts to correlate many subtle attacks over a long period of time from similar places (such as the same school, ISP, etc)
- kranner 16y agoThat's interesting. I've never admin'ed a server before so I hadn't thought about this at all. It'll probably be useful to me to keep more verbose access logs and hash IP addresses to track what individual users (at least those not behind a group firewall) are up to. Thanks for the tip!
- bl4k 16y agoYou should be most paranoid when you see/hear nothing
- jon_dahl 16y agoAt the moment, I don't hear/see ninjas sneaking up on me, hackers taking down my web app, a terrorist plot, or the shadow government spying on me. Oh crap.
- ax0n 16y agoPlease. No attack is perfectly stealth. Keep in mind I've played both sides of this game. People who know how attacks work in the wild can usually spot things that might not raise the ire of average sysadmins.
- bl4k 16y agoSo you are saying that in 2 minutes that you aren't watching logs somebody can't gain access, clear out the IDS and other logs and reset tripwire?
- ax0n 16y agoNo, I'm saying an attacker would also have to find and destroy the immutable central logging store that all the stuff goes to. They'd also have to reach through the sands of time to get the stuff that's already been blowing up my phone. Get over yourself. It's worth mentioning that no one is perfectly secure, either. A sufficiently bored, persistent and motivated attacker WILL find some kind of way in. I'll give you that. I've seen it play out enough times. But with centralized logging, transaction shipping for hot-site replication, and sufficient effort placed on separation of duties, an organization can minimize the impact a successful attacker can have, and can ensure that all audit trails remain intact in some way or another.
- jasonkester 16y agoYeah, it took reading the entire article to figure out what the site in question is for and what it does that allows regular users to reinstall the kernel on one of his machines. The first several times I read the term "code evaluator", it never occurred to me that he really meant evaluator as in executing user-supplied code on his server. Holy yikes! Reading the rest of the article, it does seem that he's at least thinking about how to deal with the ramifications of that decision. It certainly takes some boldness to try this at all. Personally I would have got as far as "executing user-supplied code", thought about it a second, shivered at the implications, and picked a different idea to run with.
- kranner 16y agoThat blog post is one in a series of ongoing commentary about the site, so I don't usually explain the idea again. I guess it really is confusing out of context. The code evaluation runs in a standalone server. I hope to learn what to block over time against a series of successful exploits. Evaluations that failed to compile/run/return-an-expected-result are marked on another server (on which they are not evaluated in any way) so I can study them later.
- jasonkester 16y agoYeah, like I say, Hats off to you for even trying. Sounds like it will be a fun site to run, since I bet you'll be battling against would-be hackers full time from here on out.
- kranner 16y agoMy sarcasm-o-meter flew off the wall. Well, I'm not deterred yet: 1. It may not be an insurmountable problem; see eru's and ambition's suggestions below. 2. There is a real business need for the application, and anything worthwhile can have unforeseen difficulties.
- jasonkester 16y agoNo sarcasm intended. (wish there was an HTML tag for <nosarc>). Fun as in intellectually challenging with a constant stream of new baddies to battle.