10 ms·
I would wager that they're opening it in order to generate a thumb or preview, or maybe for search indexing, and libreoffice is a good way to achieve this on li
by madaxe 13y ago
I would wager that they're opening it in order to generate a thumb or preview, or maybe for search indexing, and libreoffice is a good way to achieve this on linux - particularly if they're only opening it once, as they probably use the hash of the file.
We do exactly this on our eCommerce platform, before wanging stuff into s3 or glacier and just keeping a reference kicking around.
On the other hand, you have just discovered an information disclosure (host IPs) vulnerability in dropbox.
- tptacek 13y agoThis seems unsafe; if I understand what this person has done, he'd essentially be coercing Dropbox's backend services to open arbitrary links on his behalf. That's a very dangerous capability to expose to adversaries.
- rpledge 13y agoOr worse, if as other threads are speculating, libreoffice is being used to generate previews of the docs then an exploit in libreoffice could be used to get access to dropbox's backend
- milkshakes 13y agoto be fair, it's possible that dropbox understands this and has taken steps to sandbox and isolate the process that does this fetching from the rest of their internal infrastructure. if this is done for the purposes of generating thumbnails/online previews, and the .doc includes external resources, what other choice do they have but to fetch it?
- MiguelHudnandez 13y ago> what other choice do they have but to fetch it? They could not fetch it and have a little blank bit in the thumbnail. Chances are they're using a library they didn't develop and did not think of the possibility of external resources being loaded. Edit: The most secure way I can think to handle preview generation is to have a virtual machine firewalled from the internet that previews a single document and is then reverted.
- Kudos 13y agoIt makes more sense to have it fetch them via a proxy.
- fleitz 13y agoFetching via a proxy really doesn't do much, all you lose is the originating IP of the machine, the rest of the vulnerability still works. If you're thinking of egress filtering except for the proxy, you can just HTTP tunnel right through it.
- MiguelHudnandez 13y agoAlso there's a possibility of processing embedded links which point at your internal network. "How did this HTTP GET go through to my 'firewalled' PHPmyadmin site?" You have to treat all user input as if it's toxic.
- fleitz 13y agoBrilliant! I wonder what kind of error messages LibreOffice embeds when it can't fetch a resource... could map out the internal network pretty quickly if it has distinct error messages. Also docx files are zip files which opens the possibility of a zipbomb. I wonder if LibreOffice has protection for zipbombs.
- 13y ago
- abstractbill 13y agoThe machine isn't the only thing at risk. Given this setup, it seems possible to use dropbox nodes to ddos an external target, just by uploading lots of documents, each containing lots of these links. It doesn't seem like they should be fetching external resources at all.
- milkshakes 13y agoagain, it's not inconceivable that they understand this as well, and have some sort of rate limiting system in place. do you have a problem with google docs converting your office files?
- werid 13y agoThere was a case awhile back where Google docs helped a guy rack up a huge AWS bill. http://www.behind-the-enemy-lines.com/2012/04/google-attack-how-i-self-attacked.html http://www.behind-the-enemy-lines.com/2012/04/google-attack-...
- veidr 13y agoWow that is an interesting blog post, with a happy ending to boot (Amazon refunded the $1000+ in bandwidth fees, due to the accidental nature of the usage).
- danielweber 13y agoThere are lots of services that generate traffic on your behalf. A very general rule is that you should have to send at least as many bytes as the service does, lest you become a DDOS multiplier. I don't see a .doc file getting small enough to outsize a HTTP request inside of it, even if you used some funky compression, but I'm willing to hear otherwise. One question would be if you could upload the document once and then somehow trigger a very tiny edit that causes them to rescan it.
- abstractbill 13y agoOne question would be if you could upload the document once and then somehow trigger a very tiny edit that causes them to rescan it. That does seem likely - dropbox tries to only upload diffs, when a file gets changed: https://www.dropbox.com/help/8/en https://www.dropbox.com/help/8/en
- UnoriginalGuy 13y agoIt is possible but DropBox doesn't exactly have a good record on security.
- njharman 13y ago>> what other choice do they have but to fetch it? Firewall unexpected outbound connections on machines doing their processing.
- wildmXranat 13y agoThis x 10. If opening doc files is a planned feature, doing a request to these embedded URLs doesn't sound too good at all.
- snowwrestler 13y agoI'm more concerned about the concept of a document that can issue a GET request just by being opened. It sounds exactly like a phishing payload.
- glitch003 13y agoWhy? Person embeds image in the doc or html file http://2.bp.blogspot.com/-iarq5sjWDWc/TWRxt8nPegI/AAAAAAAAA_0/ABabl2TlOO0/s320/emu.jpg http://2.bp.blogspot.com/-iarq5sjWDWc/TWRxt8nPegI/AAAAAAAAA_... and then when the document is opened, Word (or LibreOffice in this case) tries to pull down the image to display it. Nothing fancy.
- anonymouz 13y agoIt should at least ask if there are remote resources embedded. Like e-mail clients do.
- badman_ting 13y ago"Person puts some characters in the query string, and the web application reads it. Nothing fancy." I just described SQL injection.
- fphhotchips 13y agoSQL Injection isn't fancy. That's why it's such a bad vulnerability.
- Too 13y agoCreate a text file on your desktop, called hack.html, with the following content. <img src="https://news.ycombinator.com/y18.gif" /> Double click to open with your favorite browser.
- fleitz 13y agoYup, it's massively unsafe, find a bug in LibreOffice, write exploit, gain control of the doc thumbnail servers, read everyone's newly submitted docs.
- tlogan 13y agoI wonder if you know which storage provider does not do this. As far as I each of these storage providers offer preview (including embeded images) thus they do need to open arbitrary links.
- altrego99 13y agoWhy would they open the .doc and allow it to run whatever embedded macro which does the job of calling home?
- joe_the_user 13y agoParent: I would wager that they're opening it in order to generate a thumb or preview, or maybe for search indexing Article: Uploaded Documents to Dropbox Personal Account with Private Folders So drop box indexes and creates thumbnails for private documents? This is because the NSA gives a bounty for friendly UIs, perhaps?
- skeletonjelly 13y agoWhat's wrong with thumbnails for private documents? Thumbnails are thumbnails.