7 ms·
Anyone exposing CUPS to the internet is living a level of not giving a fuck that CVEs cannot reach.
by RGBCube 2y ago
Anyone exposing CUPS to the internet is living a level of not giving a fuck that CVEs cannot reach.
- amluto 2y agoAnd, for some utterly and completely absurd reason, CUPS runs as a system daemon instead of a highly sandboxed user program.
- bshipp 2y agoThis is the worry. It seems like a really unnecessary privilege escalation.
- jeffbee 2y agoIt's because of the frankly idiotic idea of persistent print queues. If you want to have this artifact that survives a user session, then the print subsystem needs super-user abilities. ChromeOS does away with the whole idea. There are no persistent printer queues or jobs. Artifacts of the printing subsystem have lifetime tied to the user session.
- funcDropShadow 2y agoNo, persistent print queues can be implemented without cups running as super-user.
- gordonfish 2y agoI'm a little confused why this is even an issue. Persistent queues have been an option since the days of Windows 9x. Maybe it's a Gnome problem. KDE let's me see what I had previously printed if I want to see it, or reprint something. I also know many people in pre-press who make good use of that.
- amluto 2y agoWindows 9x printing was every bit as bad as CUPS.
- gordonfish 2y agoThe point was about the retention of print jobs in queue, that it was a concept and option since the mid 90s.
- throwanem 2y agoIt's a spooler for a printing system that supports concurrent job submission, potentially among multiple users. It's going to have to achieve serialization some kind of way.
- aftbit 2y agoWhy does it need to run as `root` user and not `cups`?
- stevekemp 2y agoBinding to ports under 1024 traditionally requires root privileges. (These days of course that isn't quite as true as it used to be.)
- amluto 2y agoWhy on Earth do ordinary systems need CUPS binding to a port at all?
- a96 2y agoThey don't need. Want, for listening to network printers announcing themselves. It's a very bad system, even then.
- amluto 2y agoHave you ever seen a network printer announce itself by talking to a print daemon on port 631? I’ve seen network printers announce themselves over DNS-SD/mDNS and over NetBIOS, AppleTalk, etc. All of those are a layer beneath the print daemon.
- yrro 2y agoThey don't. cups-browsed is a legacy component that isn't needed on ordinary systems, which outsource printer discovery to an mDNS service such as avahi.
- edelbitter 2y agoOn Ubuntu, both. A system daemon with interesting interactions with avahi-daemon and colord, and a somewhat sandboxed user program, just so Chrome is not overly inconvenienced by its snap sandboxing. But wait, there is more: The login & lock screen also runs the whole glory of GNOME.. to query printer settings. So you can have those sweet, sweet "new printer" notifications overlaid while inputting your password. Or whatever else "your" printer needs to add there.
- jmclnx 2y agoFWIW, on OpenBSD, cups-browsed is not on my system, but there are some cups files. But cups-browsed is installed when you install packages "net/avahi" and "print/libppd" which I do not know what either of them are. So I guess on Linux avahi needs cups-browsed.
- RGBCube 2y agoI also cannot believe that this is the 9.9 rated CVE. For comparison, heartbleed was a 7.5. I was awaiting a Total Linux Meltdown at best and a collapse of the world economy at worst with the amount of hyping up and fearmongering that the author did on social media.
- bogantech 2y agoLink to the OP for those that haven't seen it: https://x.com/evilsocket/status/1838169889330135132 https://x.com/evilsocket/status/1838169889330135132 Hyped it up to be some massive thing but it turned out to be a massive nothingbuger for me at least
- RGBCube 2y agoNon-loginwalled link: https://threadreaderapp.com/thread/1838169889330135132.html https://threadreaderapp.com/thread/1838169889330135132.html
- maeln 2y agoIt's always funny to me how cybersecurity always seem to attract people with a ... certain sense of ego.
- evilos 2y agoThey claim to not be a cybersecurity pro
- ChocolateGod 2y ago> pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more. I can think of another reason they got patronised.
- deleted 2y ago[deleted]
- NavinF 2y ago
- DanMcInerney 2y agoIt appears that the vulnerable service in question listens on 0.0.0.0 which is concerning, it means attacks from the LAN are vulnerable by default and you have to explicitly block port 631 if the server is exposed to internet. Granted, requires user to print something to trigger which, I mean, I don't think I've printed anything from Linux in my life, but he does claim getting callbacks from 100's of thousands of linux machines which is believable.
- gordonfish 2y agoThis is why on public servers I block everything inbound and only allow specific needed services through.
- bongodongobob 2y agoWho doesn't block all unneeded ports on an internet facing server or have it behind a firewall of some sort?
- bshipp 2y agoI guess the important question is whether or not these things are blocked by default or require user intervention to disable cups? Sure, many of us block all ports by default and either route everything behind a reverse proxy or punch very specific holes in the firewall that we know are there and can monitor, but someone firing up an ubuntu distribution for their first foray into linux is probably not thinking that way.
- bongodongobob 2y agoWell lots of people crash 600HP cars right after they buy them. If you haven't done your homework, you'll learn quickly.
- bshipp 2y agoThe people who are crashing their 600HP Linux systems are, unfortunately, not the ones who are reading CVE listings in their spare time. Canonical and other distros are probably going to have to patch that default setting.
- johnklos 2y agoAnyone going to a coffee shoppe and using a public wifi is exposing CUPS and can be exploited. Simple minded dismissal doesn't help anyone.
- gordonfish 2y agoHonestly, this is why firewalls exist. This really isn't problem for anyone with basic computer hygiene.
- zanecodes 2y agoThe prevalence of attitudes like this in the Linux community is why the year of the Linux desktop will never come. Imagine if your brand new refrigerator, by default, would leak toxic refrigerant into your kitchen unless you adjusted a valve just so. This fact is not called out prominently in the manual, but if you read the fine print in the manufacturer's assembly instructions and have a working knowledge of how a refrigerator operates, you can maybe infer that this valve must be adjusted after purchase to prevent leakage. You go on their support forum to try to figure out why your brand new refrigerator is emitting toxic refrigerant, and you're essentially called an idiot and told you don't have "basic refrigerator hygiene." People don't want to become refrigerator mechanics. They want cold food.
- abhinavk 2y agoWhy isn't the firewall on by default on desktop systems?
- snickerer 2y agoBecause you don't need a firewall on a sensibly configured desktop computer. If you have daemons that listen to incoming connections, you only want to run them if they are sane and secure. A firewall makes sense when you don't trust the daemons in your lair, eh, network, and you don't have the possibility to replace insecure stuff with secure stuff. But a firewall must be maintained by experts. For a single computer it is much easier: just make sure it is secure and don't add an extra layer of complexity to it.
- ImpostorKeanu 2y agoLateral movement and privilege escalation are total wins, tho.
- eadmund 2y agoIt sounds like in this case “exposing CUPS to the Internet” means “running a Linux desktop on the Internet” which while not something I would do doesn’t seem crazy. I would hope that a default Debian desktop installation would be secure enough to set up without a firewall. I certainly expect that a Linux laptop shouldn’t be highly vulnerable to every other device on, say, an æroport’s WiFi.
- rollcat 2y ago> I would hope that a default [OS] desktop installation would be secure enough to set up without a firewall. The OS you have in mind is called OpenBSD, which has had two remote holes in the default installation in about 3 decades; and if you don't need to run Linux-only applications, it actually is a pretty decent desktop. I don't blame Linux distributions however - both Windows and macOS are way worse. We've been living through a crisis of complexity, everyone is keen to call out Electron apps but we keep on installing and using them. As long as we accept this complexity, things will keep getting worse.