RE: [VulnDiscuss] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Password
Michal Zalewski <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 30 Jan 2003, Dave Ahmad wrote:
> Of course not. That is a silly example and not really an interesting
> problem -- I am not saying that all memory, everywhere, should be
> scrubbed because of the possibility that it could store something
> sensitive.
The example is silly if you do not consider the problem a vulnerability in
the first place, and I was trying to make my case to David Endler, who
seemed to have a different opinion. iDefense advisory refers to the
problem as a vulnerability, and says that some clients are vulnerable,
others not.
> Scrubbing buffers used to store credentials, keys, etc after they are no
> longer necessary is good practice, that is all.
That's exactly what I'm trying to say. Considering this a vulnerability is
sort of far-fetched, and this is why I can understand people who attempt
to dismiss this as a non-issue on a vulnerability disclosure forum - in
that I do feel uneasy about seeing it reported as a full-blown
vulnerability.
> Perhaps, but I don't feel as strongly as you do. You can read memory
> with format string bugs and there have been other vulnerabilities where
> memory is output.
Which is exactly why it's a good practice, and still not a vulnerability
per se. And following this practice does not render format string bugs and
memory viewing vulnerabilities useless, either. Once again, just a reason
why I think it's a bad thing to say one client is vulnerable, another
client isn't.
Perhaps I'm not making myself clear, for which I apologize - I'm not
trying to dismiss the concept of following this security practice. There
is some value to it, and the cost is almost zero.
--
------------------------- bash$ :(){ :|:&};: --
Michal Zalewski * [http://lcamtuf.coredump.cx]
Did you know that clones never use mirrors?
--------------------------- 2003-01-30 15:26 --