12 ms·
Hunting for Nginx alias traversals in the wild
- sneak 3y agoNote that this leaks the vault with secrets encrypted - a leak of the cyphertext. > This vulnerability has been disclosed to Bitwarden and has since then been fixed. Bitwarden issued a US$6000 bounty, which is the highest bounty they issued on their HackerOne program. That's a ridiculously low payout.
- dghlsakjg 3y agoI don’t know enough about bounty programs to comment on the amount, but my understanding is that leaking encrypted secrets isn’t really dangerous?
- NoZebra120vClip 3y agoIt's generally a question of time. If you want to play the long game and collect a lot of encrypted data now, you can simply wait until it is possible to trivially decrypt, and/or start cracking now and let the years work on it. Most encryption decisions are framed as a tradeoff of the time and resources it would currently take to brute-force your way through it, and how many years before a simple attack becomes feasible, vs. your $5 wrench attacks in the present day.
- nyolfen 3y agoBW uses 100K rounds of PBKDF2 for the master password so I don't think that will be any time soon
- SV_BubbleTime 3y agoBW now uses Argon2 over PBKDF. I can’t remember if that is by default, opt-in, or new accounts. But barring an argon vuln, this is even less of a concern. Also, I think BW has been using more than 100k for some time now. Last I saw 600K was the recommendation.
- emaciatedslug 3y agoThe default for new Bitwarden accounts from Feb 2023 on is PDBFK2 HMAC SHA 256 setting at 600,001 iterations on the client and 100,000 on the server with the option to use Argon2id. These settings are above current OWASP recommendations. https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2 https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor... https://bitwarden.com/help/kdf-algorithms/ https://bitwarden.com/help/kdf-algorithms/
- NoZebra120vClip 3y agoAll the replies have given random statistics, but these don't shed much light on the length of time it may take an attacker to brute-force a password, or find a chink in the armor of the vault's encryption algorithm. Now as I said, a significant threat actor with lots of time in their future plans can collect encrypted stuff such as vaults and bide their time. Someday, the decryption may be cost-effectively cheap. Someday, a flaw may be uncovered in the cryptography. Someday, a vault owner's secret key(s) may leak and can be correlated. As I said, it's just a question of time, and the ability to hold on to your cards for long enough that they can be played in the proper manner. It may take 5 years, 10 or 20, but if the payoff is valuable enough, it's worth the wait for the threat actor.
- SV_BubbleTime 3y agoThere is practically zero scenarios where hacking ANY bitwarden account 20 years from now nets you anything useful. If the concern is general encryption when you were concerned about a 20 year from now scenario, don’t send it.
- NoZebra120vClip 3y ago> There is practically zero scenarios where hacking ANY bitwarden account 20 years from now nets you anything useful. Bitwarden is a password manager, yes? What about cloud accounts of someone's employer, like an AWS account that runs $1,000,000 of monthly assets? That wouldn't be valuable in 20 years? What about VPN credentials for some big tech intranet? Yeah, hopefully they use MFA and they expire passwords before 20 years, but just in case, right? I can certainly see nation-state actors hanging on to juicy encrypted password manager vaults, just on the off-chance they could hit the jackpot. I can think of plenty of accounts that would still be valuable and enabled 20 years from now.
- rcxdude 3y agoa password vault contains a lot of long-lived secrets protected by a human-provided key, so it's really not something you want out there, even encrypted.
- Bluecobra 3y agoI would assume most people that are doing self-hosted are securing it behind a VPN like Wireguard instead of opening it to the whole web. (at least I hope so)
- donutshop 3y agoI thought so too. But then did a quick search on Shodan and found these: https://www.shodan.io/search?query=bitwarden https://www.shodan.io/search?query=bitwarden https://www.shodan.io/search?query=vaultwarden https://www.shodan.io/search?query=vaultwarden
- diarrhea 3y agoI am not. Working well so far. My instance is behind Caddy, behind a secret URL path. To talk to the instance, this “pre-shares secret” needs to be known first. So far I haven’t seen any abnormal hits. I’m closing in on 3 years of using it in this setup, via Vaultwarden. I’m aware that this is security through obscurity. The instance’s accounts use strong passwords and MFA.
- BOOSTERHIDROGEN 3y agoIs this can work for mobile devices ?
- diarrhea 3y agoYeah, the full URL can be specified in Bitwarden clients (browser extension, mobile app) and then never touched again. The secret path only leaks if users use Bitwarden's sharing feature. It's not a "pre-shared secret" in that sense, as it can publicly leak by design.
- dw33b 3y agonot compared to the $500 Google gave them
- gostsamo 3y agoNot sure why your comment is last in the page. Google have significantly more resources and the authors looked to disagree with the amount awarded for the google vulnerability.
- andersa 3y agoSmall companies can't just give out $50k bounties, even if it would be deserved.
- Decabytes 3y agoGlad that the leaks are still encrypted. Even companies that specialize in this sort of stuff are not immune to leaks, so this is honestly the best case scenario.
- 542458 3y agoAt risk of asking a dumb question, is there any good reason that you’d want nginx to allow traversing into “..” from a URL path? It just seems like problems waiting to happen. Edit: Actually, I’m a bit lost as to what’s happening in the original vuln. http://localhost/foo../secretfile.txt http://localhost/foo../secretfile.txt gets interpreted as /var/www/foo/../secretfile.txt or whatever… but why wouldn’t a server without the vulnerability interpret http://localhost/foo/../secretfile.txt http://localhost/foo/../secretfile.txt the same way? Why does “..” in paths only work sometimes?
- SahAssar 3y agoNot in any "normal" use-case, no. It'd make sense to make this behavior opt-in, like having a `allow_parent_traversal on;` flag in the location.
- aidenn0 3y agoJust guessing, but NginX probably either checks for "/foo/bar/.." and disallows it, or normalizes it to "/foo/" but "/foo/bar.." is a perfectly valid file name, so it doesn't get caught by the net checking for this.
- lyu07282 3y agoThat has been a known issue in nginx for a very long time and its a common attack vector at CTFs: https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/nginx https://book.hacktricks.xyz/network-services-pentesting/pent...
- magicalhippo 3y agoThere is a LFI vulnerability because: /imgs../flag.txt Transforms to: /path/images/../flag.txt I've only implemented a handful of HTTP servers for fun, but I've always resolved relative paths and constrained them. So I'd turn "/path/images/../flag.txt" into "/path/flag.txt", which would not start with the root "/path/images/" and hence denied without further checks. Am I wrong, or, why doesn't nginx do this?
- kibwen 3y agoIf all you need is a simple way to serve static files that minimizes resource consumption and is reliably secure, what is the state of the art these days? In the past I would probably reach for Nginx, but I wonder if a more focused/less configurable tool would be preferable from a security standpoint.
- adventured 3y agoCaddy is pretty simple to configure and serve static files from.
- francislavoie 3y agoShameless plug: Caddy does a great job here. Automatic HTTPS, written in Go so memory safety bugs are not a concern, has a solid file_server module.
- username135 3y agoIsn't everything forced to https now
- ehnto 3y agoBrowsers try to navigate you to HTTPS but no, http the protocol is still working as it always has. Both nginx and Apache will require configuration to serve HTTPS. You might still use HTTP on an internal network in a DMZ or other trusted network.
- username135 3y agoGood to know
- housemusicfan 3y agoNo. Some things were never meant to be, like downloading CRLs over HTTPS.
- princevegeta89 3y ago
- amluto 3y agoHow is this not seen as a vulnerability in nginx? This behavior is utterly absurd, seems to have no beneficial purpose, and straightforwardly exploitable.
- housemusicfan 3y ago[flagged]
- kibwen 3y agoAnd a good carpenter understands that tools can be better or worse, and that a good carpenter who uses bad tools will be worse off than a good carpenter who uses good tools. It's not wrong of anyone (regardless of skill level) to demand better tools; power is not a blanket excuse for poor design. You can have powerful tools with non-dangerous defaults.
- tempest_ 3y agoThat idiom is so dumb. There are 1000s of jobs that are incredibly easy with the tool for exactly that job but painful without, the auto industry alone has tonnes. Software with footguns can be improved by removing the footguns.
- phendrenad2 3y agoFalso dichotomy. Tools can be "powerful" without being easy to misconfigure. To use a carpenter example, circular saws have guard shields that snap into place if the saw is free in the air. Seems like a good thing, no? Are saws meaningfully less "powerful" because of this security feature?
- housemusicfan 3y agoShall we make straight razors illegal too while we're at it? Let's not reduce everything to the least common denominator lest we end up like (formerly) Oregon where you couldn't pump your own gas because it was "dangerous" for the lay person.
- whiskeymikey 3y agoThis is probably a dumb question but why would Bitwarden allow unauthenticated requests to /attachments at all? Even with the Nginx bug, wouldn’t the request have failed if that URL required authentication?
- Someone1234 3y agoThis is an exploit against the web server's configuration, so never executes Bitwarden's authentication code or any Bitwarden code at all. It isn't unusual or incorrect for projects to use their own authentication rather than Nginx or a module. It is still Bitwarden's responsibility since they shipped a dangerous configuration via Docker. Which they seemingly acknowledge and have since fixed.
- whiskeymikey 3y agoAhh okay. That explanation makes sense. Thanks!
- autoexec 3y ago> It is still Bitwarden's responsibility since they shipped a dangerous configuration via Docker. Which they seemingly acknowledge and have since fixed. The screenshot makes it look like the docker setup option was still in beta and the page had warnings all over it saying there could be possible issues. I can't really judge Bitwarden too harshly here for releasing something in beta that was later found to have a vulnerability in it.
- brigandish 3y agoThe article didn't mention permissions, would this still work if the nginx user is denied permissions on things like `/var/log`? I suspect it wouldn't but isn't the most common cause of security flaws going to be unchecked assumptions? As an aside, I didn't know Github code search accepted regex.
- VWWHFSfQ 3y agono it wouldn't work if the user nginx is running as didn't have read access to the directory or files
- komali2 3y agoAh then I just realized, it probably does have access to all nginx log directories, because nginx needs write permissions to them anyway, right? Now I really want to go double check all my permission setups...
- crote 3y agoIt depends on how nginx is designed. In theory you could separate log writing into a different process, and drop those permissions from the worker process. Or just write to stdout and have systemd handle the logging for you, that'd work too.
- andrewstuart 3y agoI dropped nginx because it was really fiddly to configure and misconfiguration has potentially bad consequences.
- evgpbfhnr 3y agoFWIW gixy (nginx configuration checker) catches this: https://github.com/yandex/gixy/blob/master/docs/en/plugins/aliastraversal.md https://github.com/yandex/gixy/blob/master/docs/en/plugins/a... (and nixos automatically runs gixy on a configuration generated through it, so the system refuses to build <3)
- wredue 3y agoI just gave nix a go and so far it seems great. But do you know, if they’re a nicer options finder? The one I found where you just search all several thousand options kinda sucks. I want to just see my package (say, ssh) and just the ssh options, but the results get littered with irrelevancy.
- evgpbfhnr 3y agoWhen I roughly know what I'm doing I use search.nixos.org; if you give it the full services.foo prefix it's usually relevant enough, e.g. for ssh you'd want "services.openssh", which you can find skimming through the results of just searching 'ssh' first: https://search.nixos.org/options?channel=unstable&from=0&size=50&sort=relevance&type=packages&query=services.openssh https://search.nixos.org/options?channel=unstable&from=0&siz... For anything I'm not 100% sure will be obvious I search through a local clone of the nixpkgs repo directly, but I'll be honest and say I just never took time to search for a better tool
- JasonSage 3y agoMy main usage of Nix is on non-NixOS machines, and I use Home Manager, and while it has a similar problem, just searching the options in the packages it provides configuration for is a smaller issue. Not sure if this helps you at all or not, it really depends on your usage of Nix, but for managing user configuration I do recommend Home Manager.
- smoldesu 3y ago> if they’re a nicer options finder? https://mynixos.com/ https://mynixos.com/ > I want to just see my package (say, ssh) and just the ssh options https://mynixos.com/nixpkgs/options/programs.ssh https://mynixos.com/nixpkgs/options/programs.ssh
- kentt 3y agoIf I understand correctly, this is a vulnerability in self-hosted Bitwarden only. Is that correct?
- emaciatedslug 3y agoYes, per the article: "Bitwarden also offers a self-hosted option for those who want to maintain their own server, which is the one we are going to examine."
- zeeZ 3y agoThis is for the single image self-hosted setup method, which is still in beta. The current supported self-hosted setup is a script that creates a bunch of individual containers for the different services.
- phendrenad2 3y agoThis has nothing to do with bitwarden. This is a generic directory traversal attack (enabled by Nginx's configuration language being full of serious gotchas).
- ComputerGuru 3y agoIt does have to do with BitWarden: they wrote and shipped the buggy config.
- technion 3y agoOK hear me out: a Linux capability like option that removes the .. option from the kernels file name parser. Like web apps have been seen various bypasses involving somehow smuggling two dots somewhere since we were on dial up modems. It's time to look for a way to close this once and for all, as the Linux kernel has done with several other classes of user land bugs.
- loeg 3y agohttps://man7.org/linux/man-pages/man2/openat2.2.html https://man7.org/linux/man-pages/man2/openat2.2.html RESOLVE_BENEATH (FreeBSD has this in ordinary openat(2) as O_RESOLVE_BENEATH.)
- m00x 3y agoThat would break so many things that it would be insane to do. You could just run nginx as a separate user with very limited rights, or just run it on Docker. This, plus updating regularly usually fixes 90% of security issues.
- martinflack 3y agoBut the issue is -- would it break the things a web server is doing? It doesn't have to be a universal solution.
- archi42 3y agoMost (I hope all) distributions already run nginx as a separate user. It's best practice. But that won't help if you alias to "/foo/bar/www" and the the application has a SQLite database at "/foo/bar/db.db", which the nginx user has to have access to. Same if you run it in a container (or lock down permissions using systemd).
- franga2000 3y agoThere is no reason the web server needs to have access to the database file, the application that needs it should be running under a different user.
- jand 3y agoPlease excuse the silly question: Would proper directory and file ownerships not prevent this traversal? If nginx does not run as root, how can it read other files than the ones explicitly assigned to the nginx user?
- NoMoreNicksLeft 3y agoI don't know about everyone else, but at this point I'm no longer doing a proper installation of nginx for personal stuff. I always just spin up a docker image... and I'm not checking if it runs as root or not, really. Probably really screwing things up. Ouch.
- frays 3y agoYou are correct. Unfortunately, nginx (and other web servers) generally need to run as root in normal web applications because they are listening on port 80 or 443. Ports below 1024 can be opened only by root. A more detailed explanation can be found here: https://unix.stackexchange.com/questions/134301/why-does-nginx-starts-process-as-root https://unix.stackexchange.com/questions/134301/why-does-ngi...
- guraf 3y agoNginx is started as root but it does not run as root, it changes its user after opening log files and sockets. (unless you use a lazy docker container and just run everything as root inside it).
- jand 3y agoEven in (the official) docker image, a nginx user is created: (latest, layer 6) /bin/sh -c set -x && groupadd --system --gid 101 nginx && useradd --system --gid nginx --no-create-home --home /nonexistent --comment "nginx user" --shell /bin/false --uid 101 nginx ..... [1] https://hub.docker.com/layers/library/nginx/latest/images/sha256-d2b2f2980e9ccc570e5726b56b54580f23a018b7b7314c9eaff7e5e479c78657?context=explore https://hub.docker.com/layers/library/nginx/latest/images/sh...
- 3y ago
- gostsamo 3y agoThe title is significantly editorialized. The post title is: Hunting for Nginx Alias Traversals in the wild and the hn submission highlights the bitwarden vulnerability while there is a google one discussed as well.
- dang 3y agoOk, we've reverted the title. Submitted title was "Leaking Bitwarden's Vault with a Nginx vulnerability".
- em1sar 3y agoOkay so I self-host Vaultwarden, what do I need to do to fix the vulnerability? The article mentions another flavor of the self hosted docker image though.
- jve 3y agoI have nginx-proxy docker container on top of vaultwarden - there aren't any alias directives there. Vaultwarden itself appears to use rust with some http framework called "rocket" [1]. Sorry I'm not familiar with rust world. But anyways, said vuln doesn't apply to vaultwarden. [1] https://github.com/dani-garcia/vaultwarden/blob/19e671ff25bffa47424b5af44264c2c74c2cc84b/src/main.rs#L510 https://github.com/dani-garcia/vaultwarden/blob/19e671ff25bf...
- remram 3y agoVaultwarden does not include or use nginx, and neither does its official Docker image. Unless you are using nginx yourself (you'd know) this does not affect you.
- ilyt 3y agoDon't let web server access app's code, soo many security problems solved...
- qwertox 3y agoWhat would I need to grep my nginx logs for to see if my possibly misconfigured servers were exploited? [^/]+\.\. (not adding a question mark after that regex even though I'm asking if that one would be ok)
- Xophmeister 3y agoOT but this isn't the first time I've seen someone mistake the verb "delve" with "dwelve": > ...we started dwelving into the code base... The author may not be a native speaker, but this is far from a judgement on their English. I'm just curious about the provenance of this mistake, given the scarcity of words that begin with "dw". At first I thought it was a typo -- especially on a QWERTY keyboard -- but I've seen it often enough to question this.
- leonheld 3y ago>I'm just curious about the provenance of this mistake Because of English pronunciation (pronounciation? :-P). English is extremely irregular, there are a thousand of footguns in the language - both spoken and written -, so as non-native speakers we tend to make small mistakes that stick to our brains like glue, and it's very hard to get rid of (rid off? :-P). For me it kinda makes sense to say "dwelve" because it reminds me of "dwarfs" (dwarves? :-P) that live underground!
- deleted 3y ago[deleted]
- Xophmeister 3y agoDwindling dwarves dwell dweep :)
- leonheld 3y agobtw, as a non-native, I also cannot understand why some native speakers confuse the use of "you're, your" or "there, their" or even "through, tough". To me they sound completely different!
- wccrawford 3y agoIMO, people learn language by seeing/hearing it used. And the internet is rife with misuse of language. My particular pet peeve is using "weary" instead of "wary" or "leery". I've started to hear it spoke in youtube videos now, too, so it's not just a typo.
- HenriTEL 3y ago> The Google VRP Team recognized our work by awarding us a $500 reward for uncovering this vulnerability. They believed the impact on the application wasn't severe enough to warrant a larger reward. Exposing email and private keys of GCP accounts only gives you $500 reward? WTF. Google being Google I guess.
- TedDoesntTalk 3y ago> Nginx, a versatile web server pivotal to numerous internet infrastructures, has held a dominant market share since its inception in 2004 Horse pucky. In those days, Apache httpd held dominant market share. Nice historical hijacking.