3 ms·
Don't forget 'Silence on the Wire' and 'The Tangled Web', two of my personal favorite computer security books.
by sharkbot 12y ago
Don't forget 'Silence on the Wire' and 'The Tangled Web', two of my personal favorite computer security books.
- bjornsing 12y agoThat stuff's great. But do you know why he's on my list? He doesn't seem to think it's a good idea for a shell to parse its entire environment; he seems to think that its better to use the name of an environment variable than its value to determine if it's input to the shell or not; he seems to feel somewhat less at ease with the thought of millions of HTTP request headers passing through the bash parser, relying on its myriad of parsing rules to ensure that no part of them is accidentally executed as a shell command - now or tomorrow. I must say that this shellchock thing has shaken my belief in humanity somewhat... Why is it that these are not obvious principles that we all agree on? Am I just too "oldschool" or something? :)
- MichaelGG 12y agoPart of this is reflected in things like "Robustness Principle". This encourages programs to go out of spec and be creative with inputs to make things "easier"... but it only makes things worse. SIP, for instance, has very complicated parsing rules (like HTTP) because the messages are designed to be written by hand. This introduces security holes as well as interop. But instead of recognizing this and trying to get programs to be strict, the IETF publishes a document where they gleefully list a bunch of crazy things possible in their spec, and encourage programs that guess at the intent of malformed messages.
- bjornsing 12y agoYea... That's also utterly insane...
- spc476 12y agoI'm currently dealing with SIP messages at work. My manager actually told me not to be so pedantic with the parsing as we got some complaints from other vendors (and privately, I thought: why bother with standards if you aren't going to follow them?) I ended up with logging a warning instead of returning an error. Sigh.
- MichaelGG 12y agoYou can't actually parse SIP messages unambiguously these days. Even big open source projects like Asterisk and OpenSIPS have strictly different and incompatible interpretations. I'm purely talking about parsing, not actually interpretation of the content. It's that bad. And yes, this opens up security holes when one system is trusted to read the message correctly.