3 ms·
> The attacker controlled server [...] drops .bash_aliases file to victim's home directory when the victim performs scp operation from the server. The transfer
by askmike 8y ago
> The attacker controlled server [...] drops .bash_aliases file to victim's home directory when the victim performs scp operation from the server. The transfer of extra files is hidden by sending ANSI control sequences via stderr. [...] Once the victim launches a new shell, the malicious commands in .bash_aliases get executed.
Sounds to me like everything the user executing the scp command can access can be compromised.
- leni536 8y ago> The attacker controlled server [...] drops .bash_aliases file to victim's home directory This can only happen if scp is invoked from the home directory (or from root or /home).
- reacweb 8y agoThe server could also drop a "ls" file with execution rights in current directory. If "." is in your path before /usr/bin (I have already encounter that), it may be called as soon as you type ls (generally just after the scp).
- leni536 8y agoSure, it can also drop filenames starting with a dash, filenames with spaces/newlines in it and all sorts of stuff. These can cause all kind of havoc in poorly written scripts. Having "." in your path is an obvious misconfiguration too.
- reacweb 8y agoHaving a trailing : at the end of the PATH is the same as :. and occurs quite often.
- jakobegger 8y agoThat example requires the user to copy something to the home directory. If you copy something to /tmp, or to a subdirectory of your home directory, that attack is not possible (according to my understanding)