Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #268570

Re: making Debian secure by default

From Marc SCHAEFER <schaefer@alphanet.ch>
Newsgroups linux.debian.user
Subject Re: making Debian secure by default
Date 2024-03-28 12:10 +0100
Message-ID <ImVNT-2fvh-15@gated-at.bofh.it> (permalink)
References <ImJa1-27aa-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hello,

On Wed, Mar 27, 2024 at 05:30:50PM -0400, Lee wrote:
> Apparently the root of the security issue is that wall is a setguid program?

a) wall must be able to write to your tty, which is not possible
   if wall is not installed setguid OR if people have sane permissions
   on their terminals (e.g. set to mesg n)

b) in addition, for this exploit to run, command-not-found must be
   started with the not found command as argument: in the two Debian
   releases I just tried (buster and bookworm), with bash,
   command-not-found was not installed.

The idea of the exploit is that you get a prompt for entering a sudo
password, which is a simple text (which gets more convincing because
of a recently introduced bug in wall which does not filter out terminal
escape / control sequences), then you type the root password, which
is presumably not the name of an existing command, so command-not-found
PASSWORD is run, and someone on another terminal and user can do
a ps to see that password argument if he is quick or polling.

To fix this:

a) don't type a root password / sudo password unless you know that
   it should happen

b) don't allow others to write on your terminals, in particular
   if you run priviledged commands and expect sudo prompts

c) patch wall so that its texts are always shown to be
   different from other program outputs (== filter out
   anything else than printable characters)

       THIS IS MY PREFERRED WORKAROUND :)
       (mixing controls (prompts) and data is always
        a very bad idea)

d) don't have other users on your machine / use containers.

> So.  There is a program called 'mesg',  hrmmm..

30 years ago it was common practice to use wall (to signal stuff to
users, e.g. used by shutdown(8)).

> oof.  Are there instructions somewhere on how to make Debian secure by default?

Looks like it is, by not installing command-not-found by default
(apparently Ubuntu does).  Presumably by chance.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

making Debian secure by default Lee <ler762@gmail.com> - 2024-03-27 22:40 +0100
  Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 00:10 +0100
    Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 05:30 +0100
      Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 14:40 +0100
        Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 16:30 +0100
          Re: making Debian secure by default Hans <hans.ullrich@loop.de> - 2024-03-28 16:50 +0100
            Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 19:20 +0100
              Re: making Debian secure by default Ralph Aichinger <ra@h5.or.at> - 2024-03-29 08:50 +0100
              Re: making Debian secure by default Stefan Monnier <monnier@iro.umontreal.ca> - 2024-03-29 20:10 +0100
              Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-29 20:40 +0100
          Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 17:00 +0100
            Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 21:20 +0100
          Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-28 18:50 +0100
            Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 20:40 +0100
            Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 18:00 +0100
              Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-03-29 18:30 +0100
                Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 18:50 +0100
                Re: making Debian secure by default Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-04-01 02:30 +0200
                Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-01 03:50 +0200
                Re: making Debian secure by default Roberto C. Sánchez <roberto@debian.org> - 2024-04-01 05:00 +0200
                Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-01 10:40 +0200
                Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:50 +0200
                Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:50 +0200
                Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:51 +0200
                Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:50 +0200
                Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-06 09:50 +0200
                Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:51 +0200
                Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-06 09:51 +0200
                Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-04-06 09:51 +0200
                Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:52 +0200
                Re: making Debian secure by default Charles Curley <charlescurley@charlescurley.com> - 2024-04-06 09:52 +0200
                Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-04-06 09:51 +0200
                Re: making Debian secure by default John Hasler <john@sugarbit.com> - 2024-04-06 09:51 +0200
                Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-04-06 09:52 +0200
                Re: making Debian secure by default John Hasler <john@sugarbit.com> - 2024-04-06 09:52 +0200
                Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-04-06 09:52 +0200
              Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 18:50 +0100
                Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 21:00 +0100
                Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-30 17:10 +0100
          Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 19:10 +0100
            Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-28 23:20 +0100
    Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 17:30 +0100
      Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 18:10 +0100
      Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 18:10 +0100
        Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 18:10 +0100
  Re: making Debian secure by default jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-28 00:40 +0100
    Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 00:50 +0100
      Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 05:50 +0100
  Re: making Debian secure by default <tomas@tuxteam.de> - 2024-03-28 06:20 +0100
    Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-28 06:30 +0100
      Re: making Debian secure by default <tomas@tuxteam.de> - 2024-03-28 08:20 +0100
      Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 12:20 +0100
        Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-28 12:40 +0100
          Re: making Debian secure by default David Wright <deblis@lionunicorn.co.uk> - 2024-03-28 21:40 +0100
            Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-29 10:40 +0100
              Re: making Debian secure by default David Wright <deblis@lionunicorn.co.uk> - 2024-03-30 04:00 +0100
    Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-28 15:50 +0100
    Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 17:30 +0100
      Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 18:10 +0100
        Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 21:50 +0100
      Re: making Debian secure by default tomas@tuxteam.de - 2024-03-28 18:30 +0100
        Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 20:30 +0100
          Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 20:30 +0100
            Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 21:50 +0100
          Re: making Debian secure by default tomas@tuxteam.de - 2024-03-28 21:20 +0100
            Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 17:10 +0100
              Re: making Debian secure by default debian-user@howorth.org.uk - 2024-03-29 21:50 +0100
    Re: making Debian secure by default debian-user@howorth.org.uk - 2024-03-28 22:50 +0100
  Re: making Debian secure by default Marc SCHAEFER <schaefer@alphanet.ch> - 2024-03-28 12:10 +0100
    Re: making Debian secure by default Franco Martelli <martellif67@gmail.com> - 2024-03-28 17:30 +0100
    Re: making Debian secure by default Michel Verdier <mv524@free.fr> - 2024-03-28 17:30 +0100
      Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 17:40 +0100
  Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 21:50 +0100
  Re: making Debian secure by default Richmond <dnomhcir@gmx.com> - 2024-03-28 21:50 +0100
  Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-29 16:40 +0100
  Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-31 21:10 +0200
    Re: making Debian secure by default Roberto C. Sánchez <roberto@debian.org> - 2024-03-31 21:30 +0200
      Re: making Debian secure by default gene heskett <gheskett@shentel.net> - 2024-03-31 22:30 +0200
        Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-31 23:20 +0200
          Re: making Debian secure by default gene heskett <gheskett@shentel.net> - 2024-04-01 01:00 +0200

csiph-web