RE: [VulnDiscuss] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Password

Michal Zalewski <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
On Thu, 30 Jan 2003, Dave Ahmad wrote:

> Of course not.  That is a silly example and not really an interesting
> problem -- I am not saying that all memory, everywhere, should be
> scrubbed because of the possibility that it could store something
> sensitive.

The example is silly if you do not consider the problem a vulnerability in
the first place, and I was trying to make my case to David Endler, who
seemed to have a different opinion. iDefense advisory refers to the
problem as a vulnerability, and says that some clients are vulnerable,
others not.

> Scrubbing buffers used to store credentials, keys, etc after they are no
> longer necessary is good practice, that is all.

That's exactly what I'm trying to say. Considering this a vulnerability is
sort of far-fetched, and this is why I can understand people who attempt
to dismiss this as a non-issue on a vulnerability disclosure forum - in
that I do feel uneasy about seeing it reported as a full-blown
vulnerability.

> Perhaps, but I don't feel as strongly as you do.  You can read memory
> with format string bugs and there have been other vulnerabilities where
> memory is output.

Which is exactly why it's a good practice, and still not a vulnerability
per se. And following this practice does not render format string bugs and
memory viewing vulnerabilities useless, either. Once again, just a reason
why I think it's a bad thing to say one client is vulnerable, another
client isn't.

Perhaps I'm not making myself clear, for which I apologize - I'm not
trying to dismiss the concept of following this security practice. There
is some value to it, and the cost is almost zero.

-- 
------------------------- bash$ :(){ :|:&};: --
 Michal Zalewski * [http://lcamtuf.coredump.cx]
    Did you know that clones never use mirrors?
--------------------------- 2003-01-30 15:26 --
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.