5 ms·
> this vulnerability is remotely exploitable in smtpd, ldapd, and radiusd, but its real-world impact should be studied on a case-by-case basis. For example, ssh
by procinct 7y ago
> this vulnerability is remotely exploitable in smtpd, ldapd, and radiusd, but its real-world impact should be studied on a case-by-case basis. For example, sshd is not exploitable thanks to its defense-in-depth mechanisms.
Does this mean OpenBSD will have to update the tagline on their website that says "Only two remote holes in the default install, in a heck of a long time!"?
- tptacek 7y agoYes.
- notaplumber 7y agoNo.
- anthk 7y agoHow? Show me how can I, remotely: - Login with no SSH account - Enable SSH - Change PF rules - Change the smtpd config - Enable radiusd/ldapd without being root - Running Xenocara's xlock when is not available on servers and I have no permissions
- tptacek 7y agoThis is an extremely silly set of conditions to attach to "remote hole". You can litigate it, and maybe win the argument, but you're just bold-facing the asterisk that was already next to that already-tortured claim.
- anthk 7y agoYou mean, overriding defaults as conditions to get a remote hole? Can you exploit a bare OpenBSD install by default remotely, yes or not? Everything else is bullshit.
- pvg 7y agoThis is a bit like whether Magneto can escape the Plastic Prison (yes or no) without Logan traveling back in time and altering the timeline.
- anthk 7y agoOr Trunks killing Cell.
- linusnext 7y agoSecurity is not Boolean
- anthk 7y agoBy default you can only set two service settings: Enabling sshd, or not. And sshd is, by default: - not exploitable by this bug - PF rules are not set for incoming connections The X issue. By default: - PF doesn't accept any connection to X ports to anything not coming from lo0, localhost interface Smtpd. By default: - it just listens on localhost - there is no forwarding - PF rules aren't enabled
- linusnext 7y agoShow me, as the owner of the openbsd server, how to change the default configuration to suit a purpose that exceeds the very limited set of services enabled.
- notaplumber 7y agoMost of the issues are classified as Local privilege escalation, and none of the daemons mentioned are enabled by default, sshd can be enabled in the installer, but as the quote says "sshd is not exploitable thanks to its defense-in-depth mechanisms." So, no. Still holds. Worth pointing that Linux has had a rough week as well, this one is pretty bad: https://www.openwall.com/lists/oss-security/2019/12/02/2 https://www.openwall.com/lists/oss-security/2019/12/02/2 Patch your systems.
- naniwaduni 7y agoOnce again, the "in the default install" line should be read as "as long as you don't do anything interesting".
- juped 7y agoNone of my OpenBSD machines (on which I do things) are remote-holed by this.
- anthk 7y agoNeither are mines. PF blocks everything from the beginning, and no service is listening remotely. Heck, even for _outbound_ mail I have to create a rule for smtpd.conf. Half of the HN commenters do not know OpenBSD at all.
- upofadown 7y agoSmtpd (one of the mentioned daemons) is started in a default install. It is configured to do local mail delivery and can queue up remote deliveries for programs running on the system. It only connects to localhost and does not authenticate so this exploit would be irrelevant. If one did open an authenticated mail connection on an interface accessible to the world then the exploit would allow the system to be used as a spam relay. Added: Just to be clear, this doesn't give any significant access to the system itself through smtpd even if it is configured to be remotely accessible. So not a possible remote hole. Dunno about other stuff.
- anthk 7y agoBy default PF doesn't allow shit from external connections, so no.
- yellowapple 7y ago"Default install" would be the key phrase here. By that metric, no need to update the tagline; smtpd doesn't do much by default, and SSH has other safeguards, so apparently a default install wouldn't be substantially impacted. Still sucks for those of us who, you know, actually use smtpd on OpenBSD as a mail server. Thankfully it's just my personal one and I can afford to comment out the line(s) that actually enable outbound SMTP relaying, but still.