Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.java.programmer > #40023

Re: LDAP, .setReturningObjFlag(true) and alternatives...

From Andreas Leitgeb <avl@logic.at>
Newsgroups comp.lang.java.programmer
Subject Re: LDAP, .setReturningObjFlag(true) and alternatives...
Date 2023-10-18 14:15 +0000
Organization A noiseless patient Spider
Message-ID <slrnuivq4v.1q3b.avl@logic.at> (permalink)
References <slrnuiimne.9968.avl@logic.at> <ugbmum$38ehq$1@dont-email.me>

Show all headers | View raw


Arne Vajhøj <arne@vajhoej.dk> wrote:
> On 10/13/2023 10:57 AM, Andreas Leitgeb wrote:
>>    https://app.deepsource.com/directory/analyzers/java/issues/JAVA-S1026
>> Do I misunderstand it, or is there no third option besides:
>>    - trust the LDAP-server and have received data immediately deserialized
>>    - not trust the LDAP-server and just not get the data at all.
>> 
>> Is there, maybe, a way to restrict the classes to a whitelist
>> of classes that it may deserialize, 
>> 
>> Is there, maybe, a way to just retrieve the serialized stream and
>> scrape the relevant info without full deserialization?
>
> Java deserialization of objects is known to be potential
> security problem:
> - use all memory
> - execute code in readObject method

Yes, the root-cause of this topic...

> But I assume your LDAP service is somewhat trusted (as it
> its usually provides authentication & authorization!).

That is correct.  This is primarily for learning.
The LDAP server and in particular the element that jndi
wants to eventually deserialize is trusted.  But what if
it weren't? ;-)

> So depending on security level you can:
> * decide that you trust LDAP and continue to automatic deserialize
yes, sure.

> * continue to automatic deserialize but find a way to plugin
>    a deserialization filter (assuming you are on Java 9+ where that
>    was introduced)

Ah, good to know - for future.

> * drop the automatic deserialize and redesign the data transfer
>    in some way:
>      - instead of Java object have either JSON or XML and
>        do a DOM tree parse not a binding to get the data over
>        in a Java object
>      - move the info from LDAP to somewhere else like database

Not sure if I understand this correctly...   is this a way to retrieve
the same data that is already stored in LDAP but in alternative formats,
or do you mean that the data in LDAP needs to be stored in those other
formats(e.g. json) for that to work?



PS: sorry for my late answer... the other problem about slrn and c.l.j.p
strikes again, and I needed to dig out that other machine again, to be
able to check for followups and answer. 

Back to comp.lang.java.programmer | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-13 14:57 +0000
  Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-13 11:15 -0400
    Re: LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-18 14:15 +0000
      Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-18 10:43 -0400

csiph-web