18 ms·
Security vulnerability in MySQL ubuntu
- willvarfar 14y agoI'd love to see the code; quite how they are not comparing a memcmp to 0 would be interesting to see...
- tedunangst 14y agoThere is a check_scramble function which returns a my_bool, presumably a char typedef. That function itself directly returns the result of memcmp. If your memcmp implementation returns the full range of int values (allowed), 1/256 of them will have a 0 low order byte, which will then compare equal to zero when the check_scramble call is tested. This is why real C programmers use int as their bool type. :)
- darnaut 14y ago> This is why real C programmers use int as their bool type. :) It has the same problem if a wider type (e.g. long) is assigned to it. Use _Bool instead.
- tedunangst 14y agoI was at first tempted to complain about useless pedantry, but you're right. Even if some of us still like to party like it's 1989. I should have said the real lesson is don't reimplement standard C types, poorly.
- riledhel 14y agoHere you can see a copy of the MariaDB source code and the file in question https://github.com/atcurtis/mariadb/blob/master/sql/password.c https://github.com/atcurtis/mariadb/blob/master/sql/password...
- mjschultz 14y agoHere is the fixed version of the MySQL code: https://bazaar.launchpad.net/~mysql/mysql-server/5.1/view/3560.10.17/sql/password.c#L534 https://bazaar.launchpad.net/~mysql/mysql-server/5.1/view/35... (line 534 didn't have the test()) previously)
- willvarfar 14y agoyeap, strange; I'd have thought the obvious natural code would have been: return 0 == memcmp(hash_stage2, hash_stage2_reassured, SHA1_HASH_SIZE) As in, return a bool on whether it matched. I mean, as I read it, the function returns true if they don't match?
- tedunangst 14y agoFrom the mysql commit: Date: 2012-04-06 09:04:07 UTC That's two months ago. Looking at the changelog (http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.html http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.html), they piled in a bunch of other changes like "use less disk space". This should have gone out pronto. I feel it's not the kind of thing you sit on until your next quarterly release is scheduled. [oh wait, this is worse. mysql 5.1.63 was actually released a month ago. But they only now tell us what the security bug was? Meanwhile the bad people have had a month to diff sources? Double unhappy.]
- einhverfr 14y agowow..... What ever happened to public disclosure as soon as a patch is released? I have been bit twice by problems relating to difficulties getting security fixes/announcements out in time. In my defence I was trying to patch a difficult codebase and this just took a long time. For example, there was a full SQL injection audit that took us two months to complete early on, and there was an issue of XSRF vulnerabilities which could not be effectively patched in a production release. But waiting a month to announce the security issue after the release was out strikes me as hard to justify.
- ushi 14y agoWhether a particular build of MySQL or MariaDB is vulnerable, depends on how and where it was built. A prerequisite is a memcmp() that can return an arbitrary integer (outside of -128..127 range). To my knowledge gcc builtin memcmp is safe, BSD libc memcmp is safe. Linux glibc sse-optimized memcmp is not safe, but gcc usually uses the inlined builtin version. How do you know, how the Ubuntu devs compiled their mysql server?
- dangrossman 14y agoTry to connect to MySQL as root with a made-up password several hundred times. If you successfully connect, the bug is present and you know how it was compiled.
- gringomorcego 14y agowhere is the perl one-liner :P?
- mcpherrinm 14y agoperl -e 'use DBI; for($i=0;$i<4096;$i++){DBI->connect("dbi:mysql:", "root", "nope", {PrintError=>0}) and die "Vulnerable!";}'
- deleted 14y ago[deleted]
- ushi 14y agoHehe, ok ok.
- mjschultz 14y agoWell, the Ubuntu part came from HD Moore [1]. I haven't been able to confirm it on my Ubuntu 12.04 virtual machine instance though, nor does my virtual machine appear to trigger the bug using the CVE-2012-2122 checker [2]. But, that is just my single VM instance and I would assume HD Moore knows what he is doing. [1] http://pastie.org/private/903voijkkz8nmde3yqj4rw http://pastie.org/private/903voijkkz8nmde3yqj4rw [2] http://pastie.org/4064638 http://pastie.org/4064638
- gyaresu 14y agoOne-liner: $ for i in `seq 1 512`; do echo 'select @@version;' | mysql -h 127.0.0.1 -u root mysql --password=X 2>/dev/null && break; done Via HDMOORE on twitter
- tptacek 14y agoThis is a vulnerability in the authentication scheme used in the MySQL wire protocol, meaning attackers need to be able to connect to your MySQL database directly to exploit it. Attackers should never, ever be able to connect directly to your MySQL database directly. If you can connect to your MySQL instance directly from your Macbook in your living room, fix it right now.
- jeffdavis 14y agoWhile your advice may be prudent, that does not excuse poor security.
- deleted 14y ago[deleted]
- dhx 14y ago―Attackers should never, ever be able to connect directly to your MySQL database directly. mySQLgame[1] demonstrates that domain logic can be successfully implemented within a publicly accessible database[2]. It would be better to reword your statement to: Minimise the attack surface by preventing unnecessary access There are times where public access to a database server make perfect sense. It is the reason why database servers implement TLS client certificate verification, Role Based Access Control (RBAC) and other security features which a typical application (with domain logic at the application layer) has no hope of implementing correctly. [1] http://mysqlgame.com http://mysqlgame.com [2] http://martinfowler.com/articles/dblogic.html http://martinfowler.com/articles/dblogic.html
- tptacek 14y agoI would generally avoid building applications that assume clients are going to speak directly to the database. We see a couple of them every year (it's a common pattern in enterprise applications) and they tend to be horrorshows. In any case, the typical web app deployed by HN readers has no business having an exposed MySQL port.
- 14y ago
- baconhigh 14y agowhile true; do mysql -u root mysql --password=fail; done
- jms 14y agoFor anyone running phpMyAdmin, make sure to lock it down. Here's a guide for limiting access to it by IP address via the apache config for Ubuntu users: http://mixeduperic.com/ubuntu/how-to-restrict-phpmyadmin-ip-address.html http://mixeduperic.com/ubuntu/how-to-restrict-phpmyadmin-ip-...
- jontas 14y agoJust tried the various one-liners mentioned in the comments on a hardy (8.04) release using mysql 5.0.51a and could not get in. This is a slicehost box, so I'm assuming that can be extrapolated to mean that anyone using ubuntu on slicehost is probably safe.
- taligent 14y agoBad assumption. Very, very bad assumption.
- pwaring 14y agoIt depends what version they are using. My local dev machine (using Precise) is vulnerable, so Slicehost customers running a more recent version than Hardy might be affected.
- drivebyacct2 14y agoThat's a horrid assumption, is verifiably wrong and what in God's name are you doing on Hardy? You just screamed "ignore me" three times in two sentences.
- postfuturist 14y agoI'm not the poster, but Hardy is an LTS release that is still supported in server configuration. It's quite a bit newer than Centos/RHEL 5, which is widely deployed on servers (potentially the most popular platform for existing deployments, still).
- captn3m0 14y agoThis is also important in other environments, for instance shared hosting where you may connect to localhost, or places where you may have given non-admin shell access to a developer (assuming they could not connect to mysql root user). This is a serious vulnerability. Especially since the latest ubuntu seems to be affected(I'm on mint 13, and it is) See Ready shodanhq query for latest mysql version: http://www.shodanhq.com/search?q=port%3A3306+5.5.22-0ubuntu1 http://www.shodanhq.com/search?q=port%3A3306+5.5.22-0ubuntu1
- dhx 14y agoThis vulnerability could also assist with local privilege escalation. If an attacker managers to use a vulnerability in a web application to execute code as a web user account, they can likely access the MySQL server instance via the loopback interface (perhaps a Unix domain socket too?).
- captn3m0 14y agoSo if I try logging in with phpmyadmin 256 times, will I succeed?
- darklajid 14y agoMaybe. If you roll a dice 6 times, will one result be a 6?
- deleted 14y ago[deleted]
- mattbee 14y agoI've been trying this on lots of our customers' boxes and can't exploit it - no matter how many times I've tried I always get turned away when retrying root's password, e.g. trying "while true; do mysql -u root mysql --password=baha; done" does not yield access on any of: Debian lenny 32-bit 5.0.51a-24+lenny5 Debian lenny 64-bit 5.0.51a-24+lenny5 Debian lenny 64-bit 5.1.51-1-log Debian squeeze 64-bit 5.1.49-3-log Debian squeeze 32-bit 5.1.61-0+squeeze1 Debian squeeze 64-bit 5.1.61-0+squeeze1 Ubuntu lucid 64-bit 5.1.62-0ubuntu0.10.04.1 So I'm not inclined to think it's as bad as made out by the simple exploit above.
- Negitivefrags 14y agoI would imagine you have to try a different password each time.
- dangrossman 14y agoWhy would you imagine that? The bug is that what password you provide doesn't matter.
- Negitivefrags 14y agoThat wasn't how I read it. It sounds like they were casting the result of a memcmp to a char. A char only has a range of -128 to 127. The resulting overflow means that an arbitrary password hash has a 1/255 chance of landing on 0, but you still have to try a bunch to hit one.
- mike-cardwell 14y agoThis is incorrect. You do not need to try a different password each time.
- tedunangst 14y agoThe password is combined with a random value on each attempt, the hash will change each time.
- dfc 14y agoIs the bug limited to ubuntu?
- tedunangst 14y agoThe bug is most definitely in mysql. Its manifestation depends on compiler/library, and it appears ubuntu is the most prominent afflicted platform, but there could be others. Relying on the bug being limited is very thin ice.
- pwaring 14y agoCan anyone view the MySQL bug report linked to from the email? I get 'access denied' each time I try.
- gouranga 14y agoDoesn't surprise me. Ubuntu always ship fucked up, broken, shitty MySQL versions. Look at the one that is current HEAD on 10.04 LTS. It's got so much broken stuff in it, we had to move everything to a spare windows machine where we could stick a later version on without screwing up the machine (DBs for: team city, jira, crucible).
- viraptor 14y agoWhy migrate to a completely different environment? I'd recommend just installing some version of percona server (mySQL flavour) instead. You get both better software and upstream version instead of a repackaged one.
- dawkins 14y ago"Because the protocol uses random strings, the probability of hitting this bug is about 1/256." Why 1/256?
- jontro 14y agoBecause when the return value is truncated to a char, the last two bytes in the int would have to be 0x00, which is 1/256 assuming the return value is a completley random int.
- rlpb 14y agoIt looks like this is being tracked in Ubuntu here: https://bugs.launchpad.net/bugs/1011371 https://bugs.launchpad.net/bugs/1011371 Unfortunately Oracle's stewardship of MySQL appears to be a closed model. There is no public access to their bug tracker, and distributions struggle to keep up with security updates because the details of their fixes in the source are not published. The future of MySQL appears to be in one of the MySQL forks. See https://lists.ubuntu.com/archives/ubuntu-server/2012-February/006073.html https://lists.ubuntu.com/archives/ubuntu-server/2012-Februar... and https://lists.ubuntu.com/archives/ubuntu-server/2012-February/006129.html https://lists.ubuntu.com/archives/ubuntu-server/2012-Februar... for details.
- ios84dev 14y agoWhat about http://bugs.mysql.com/ http://bugs.mysql.com/?
- brg1007 14y agoAny chance that this vulnerability is linked with the recent hashed password lists disclosure ?
- sohn 14y agoI don't think serious web applications such as LinkedIn or Last.FM use Ubuntu, but I wouldn't have thought they would had unsalted passwords stored, either.
- mmaunder 14y agoHas anyone managed to actually repro this. I've tried it on a wide variety of systems I run and no repro. Just looking for anecdotal data on how many systems are affected. To me it doesn't seem like a high percentage.
- deleted 14y ago[deleted]
- mjschultz 14y agoHere is the reference from the Ubuntu CVE tracker: https://bugs.launchpad.net/bugs/cve/2012-2122 https://bugs.launchpad.net/bugs/cve/2012-2122. So yes it looks like it is confirmed. Also, the associated bug report: https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/1011371 https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/101....
- pwaring 14y agoI can reproduce it on my Ubuntu laptop (amd64 precise), so it definitely exists.
- Apreche 14y agoI am trying to make it work on my Ubuntu 12.04 VBox VM. I have mysqld Ver 5.5.22-0ubuntu1, which is the supposedly affected version. I can not reproduce it. I thought at first it might be because I do not have a root password (it's a VM) so trying to use any password at all returns a failure before the faulty code is reached. Then I tried to login as debian-sys-maint and some other users that do have passwords, and it still did not work.
- mjschultz 14y agoI couldn't get it to reproduce on a VM (VirtualBox) either. I'm wondering if the SSE-optimized version of the glibc doesn't work the same way in a VM as it does on host hardware (i.e. SSE instructions are virtualized to some degree). Since the hardware doesn't support it, the library falls back to a version that won't trigger the bug. (Again, this is just an unconfirmed theory.)
- rominet 14y agoIt seems that SSE4 extensions are needed to be vulnerable, otherwise memcmp() is doing classical computations. So you need a 64 bits system, and be sure that you are not using a virtualisation system which does clear SSSE4 flag in /proc/cpuinfo (VirtualBox does).
- Limes102 14y ago<?php while(true) if(mysql_connect("localhost", "root", "password")) exit("connected with password: password"); I am sad to say it worked on my Ubuntu server :(