7 ms·
/bin/sh: the biggest Unix security loophole (1984) [pdf]
- zahlman 2y agoInteresting piece of history. The actual exploit techniques have a real flavour of SQL injection about them.
- supriyo-biswas 2y agoLoopholes of this kind exist these days as well. When I was working for a major retailer, who, you'd assume would have thought about these things well enough, you were prevented from executing sudo, except for being able to use it for text editing (sudo vi). I needed to install some packages with a root shell at the time, so I used the command execution feature within vi to get that.
- netsharc 2y agoIn the Middle Ages, when Internet access wasn't in your pocket all the time, I was in a hostel which had Internet kiosks, you'd put a coin in a machine, and the PC would start 2 browser windows: 1 with just a countdown, and one for you to browse. You'd have to put more coins or when the time ends the browser would be killed. Of course there was nothing else in the UI except this window and the browser, but on ancient Firefox, in the print window you had the option to specify the command line to print. I tried "xterm", hit "Print", and voila, a prompt! Using ps, I managed to figure out the difference between the unpaid browser and the paid one, and next time around I could launch a browsing session without payment...
- tiberious726 2y agoMy favorite is pressing '!' while inside a sudoed or setuid less.
- denysvitali 2y agoThere's a collection of these binary escapes: https://gtfobins.github.io/ https://gtfobins.github.io/
- more_corn 2y agoI once encountered a good anti sudo control. Execute sudo and you get a warning “log in as root instead!” Firstly, no Secondly did you just “prevent” sudo by aliasing it?
- raffraffraff 2y agoNot too mention that you can edit anything you want, like the sudoers file.
- akimbostrawman 2y agoI would assume sudoedit could have preventing that
- mingus88 2y agoAs someone who used to sysadmin and was well aware of this trick, sometimes a developer or dba will bully their way through leadership to make sure they never need to ask for permission to edit their configs We all knew it was a bad idea but when your boss and their boss say do it, it’s done. I’m pretty sure the dba (autocorrect magically suggested “diva” here) knew as well and just wanted a backdoor to have root for whatever they wanted. I later busted the same team applying patches out of band with tripwire. Hey, wonder how you pulled that off…
- NewJazz 2y agoWhy were they applying patches? And what were they patching? What were the consequences when you busted them?
- mingus88 2y agoThese were solaris 8 or 9 patches for some Oracle DB. Patch management back then was wild and conflicting patches could cause problems. Of course there were no consequences for someone bypassing the approval process and doing unscheduled changes as root. Now, if my team had made those changes without running it past the DBAs...
- fargle 2y agothey only needed a backdoor root because you're a gatekeeping dick and they wanted to get their job done without having to "deal" with your shit. OMG. they applied unapproved patches! to the product they were responsible for making work.
- mingus88 2y agolol, restricting administrative access to the administrators is pretty much a security best practice in every company everywhere. Ever heard of the principle of least privilege? They didn’t give me admin in the database and I don’t want it. They aren’t trained in the system and if you’ve ever seen what kind of mess a bunch of amateurs can make of a shared system you wouldn’t sound like such an idiot right now Ill be sure to tell the auditors that they are gatekeeping dicks for requiring change management on the financial databases
- FergusArgyll 2y agoThat's like a beginner level CTF! sheesh
- saagarjha 2y agoMy high school computer lab had an incredibly incompetent admin whose idea of security was to look through the bash history of problem students and go from there. Anyway, at one point they decided that someone had used cp to copy things to places they should’ve have been (did I mention they didn’t really understand UNIX permissions?) they decided to just remove cp altogether. So of course I made a fake cp (in Java, because that was all I knew at the time) to replace it.
- chrisding 2y agoInteresting piece of history.
- pengaru 2y agoWow, they even used the accurate term "crackers", I feel so old.
- gonzo 2y agoIf enough time passes and we don’t die, we get old. 1984 was 40 years ago.
- 0xbadcafebee 2y agoIt's nice to know that when I was born, there was a guy just like me, writing snarky annoyed memos about the stupid security holes in our systems.
- nayuki 2y agoIndeed. I learned from reading the jargon file in ~2005: http://catb.org/jargon/html/C/cracker.html http://catb.org/jargon/html/C/cracker.html , http://catb.org/jargon/html/H/hacker.html http://catb.org/jargon/html/H/hacker.html
- panki27 2y agoI had the "joy" of watching some guys from Perforce setup a new p4 instance. They confed /etc/sudoers so that the perforce user can run everything as root without providing a password. I told them that this is really a bad idea, and they pulled up one of their setup guides with "enhanced security hardening". It ended up with ~35 specific entries for binaries in sudoers, one of them being /usr/sbin/setcap - which allows you to give e.g. the Python interpreter CAP_SETUID, making a privilege escalation to root trivial again.
- dehrmann 2y agoWe love to praise Unix, but it wasn't built for modern multi-user use. FUSE was an after-thought. So were package managers, and they got added, but they require root. Users aren't sandboxed, so they can see what others are doing. These were just off the top of my head.
- fph 2y agoIs multi-user use "modern"? Back in the days everyone shared the same mainframe, now I'd say most computer systems have a single user.
- adrian_b 2y agoWhile most computers are personal computers, which have a single real human user, you still have to run a lot of untrusted programs, like the Internet browsers or whatever programs you might download from dubious sources. While perhaps the term "user" is no longer the best, there is a need even more than before to run programs with limited rights, corresponding to the rights of some pseudo-users, which should not be able to access or modify anything belonging to the real human user, unless a special permission is granted.
- calvinmorrison 2y agoSo, basically all my sandbox concerns go away if I run as root and every browser runs as its own user
- teddyh 2y ago> They did not invent UNIX but they try harder I fear that this reference to an old Avis advertising slogan may be lost to a modern audience.
- athrowaway3z 2y ago>Ritchie is the inventor of the elegant setuid concept, for which a patent was awarded. Do organization still apply for these kind of patents?
- deleted 2y ago[deleted]
- fargle 2y agoyes. most very large corps. that like to keep patent portfolios will encourage engineers to patent (assigned to the co. of course) anything slightly creative or unusual. or sometimes anything at all that sounds slightly technical. the engineer gets his name on the patent and maybe a bit of prestige. the org gets another (sometimes bad) patent in the portfolio. skimming the patent https://patents.google.com/patent/US4135240A/en https://patents.google.com/patent/US4135240A/en it seems actually pretty well drafted and pretty good (patentable).
- mixdup 2y agoSetting aside all of the technical aspects of this, the history of this in the world of UNIX, I just love the process and bureaucracy that generated this specific paper document. The very formal cover sheet (and the fact that it had an accompanying, separate, numbered instruction document), the pre-determined layout and format of a Technical Memorandum, and the fact that this was published as such a memorandum with filing and control numbers that will be researched and looked up in a library instead of just a blog or post on Medium We used to be a real society
- somytomy 2y agoDepends where you work. Judging from reading HN, 95% of all devs here are writing webshitapps for companies that don't give a flying eff about development, just profits. I develop embedded hardware for tier 1 automotive manufacturers, and we have to adhere to several ISO standards, and a number of tools for managing documentation and code hygiene. Traceability of requirements, security, functional safety, and risk assessments are associated with every single decision and every single code commit. It is a lot of documentation, but I'm a pedant and I love it. It is a design process for adults, by adults.
- mixdup 2y agoYeah, this kind of memo and process probably still exists at places like NASA as well
- 0xbadcafebee 2y agoIt's the same today, only it's webapps instead of unix utilities. Simplest bugs in the world, still devs don't pay attention to them. Simple like not sanitizing inputs, injecting stuff straight into sql queries or exec commands, dumping customer data / passwords / all environment variables into logs and error messages, etc.