Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.java.programmer > #40022
| Path | csiph.com!news.mixmin.net!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail |
|---|---|
| From | Arne Vajhøj <arne@vajhoej.dk> |
| Newsgroups | comp.lang.java.programmer |
| Subject | Re: LDAP, .setReturningObjFlag(true) and alternatives... |
| Date | Fri, 13 Oct 2023 11:15:34 -0400 |
| Organization | A noiseless patient Spider |
| Lines | 55 |
| Message-ID | <ugbmum$38ehq$1@dont-email.me> (permalink) |
| References | <slrnuiimne.9968.avl@logic.at> |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=UTF-8; format=flowed |
| Content-Transfer-Encoding | 7bit |
| Injection-Date | Fri, 13 Oct 2023 15:15:34 -0000 (UTC) |
| Injection-Info | dont-email.me; posting-host="1f3914a744276799d9c414ac3bad6cfd"; logging-data="3422778"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+ytH+4zlhbWoSKXt3xZwdXj5Y+RwveXtY=" |
| User-Agent | Mozilla Thunderbird |
| Cancel-Lock | sha1:x2Y0sPs8uG9Wamj/0+FnwDtIbNQ= |
| In-Reply-To | <slrnuiimne.9968.avl@logic.at> |
| Content-Language | en-US |
| Xref | csiph.com comp.lang.java.programmer:40022 |
Show key headers only | View raw
On 10/13/2023 10:57 AM, Andreas Leitgeb wrote:
> I've stumbled over java code, that does an LDAP query, and
> sets flag .setReturningObjFlag(true) on the searchControl object.
>
> According to some ressources, like e.g.
> https://app.deepsource.com/directory/analyzers/java/issues/JAVA-S1026
> this should be avoided, unless the LDAP server and its
> data is really trusted.
>
> I'd be curious, what would be the alternatives, under the assumption,
> that there are indeed serialized Objects stored in LDAP in whose value
> I'm really interested, and if I then didn't want to trust the server
> to always return data for the expected objects.
>
> According to description of setReturningObjFlag(): if this flag
> is false "... only the name and class of the object is returned",
> which to me sounds like I won't get the serialized data.
>
> Do I misunderstand it, or is there no third option besides:
> - trust the LDAP-server and have received data immediately deserialized
> - not trust the LDAP-server and just not get the data at all.
>
> Is there, maybe, a way to restrict the classes to a whitelist
> of classes that it may deserialize, and get an exception on
> any attempt to pull in any other class, before that other class
> is even initialized?
>
> Is there, maybe, a way to just retrieve the serialized stream and
> scrape the relevant info without full deserialization?
Java deserialization of objects is known to be potential
security problem:
- use all memory
- execute code in readObject method
But I assume your LDAP service is somewhat trusted (as it
its usually provides authentication & authorization!).
So depending on security level you can:
* decide that you trust LDAP and continue to automatic deserialize
* continue to automatic deserialize but find a way to plugin
a deserialization filter (assuming you are on Java 9+ where that
was introduced)
* drop the automatic deserialize and redesign the data transfer
in some way:
- instead of Java object have either JSON or XML and
do a DOM tree parse not a binding to get the data over
in a Java object
- move the info from LDAP to somewhere else like database
Arne
Back to comp.lang.java.programmer | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-13 14:57 +0000
Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-13 11:15 -0400
Re: LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-18 14:15 +0000
Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-18 10:43 -0400
csiph-web