RE: [VulnDiscuss] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords
David Endler <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, I'll try to address some of the main points in this thread in just one email, sorry in advance for the condensation. >I do not think it makes much sense to say that applications that do not >scrub memory are vulnerable, and those who do, are not, that's all. > 3) The attacker gains physical access to the device - for example, the > workstation is stolen. He knows what to look for in the swap file > and > is hoping to find swapped out passwords. >I agree that these issues are not vulnerabilities, however, I do think >they are worth noting. That is why we classify them as weaknesses. >I think the point here is, if you have access to this memory.. You most >likely, have access to do a lot more damage, and could probably gain the >same information using multiple methods. ok, I see that this comes down to semantics. According to the popular position (for scenario 3), no one disagrees that scrubbing passwords has value, and yet the lack of this practice by itself does not constitute a "vulnerability" since the real security issues reside in the design and access levels of the OS memory management and are independent of the ssh client. Therefore, at best, everyone is still "vulnerable" to the same issues, you've only mitigated one out of several possible attack vectors (which is not a bad thing). I can live with this description and the label of "weakness" in this case. I guess I'm not comfortable glossing over a security design problem as a non issue simply because fixing it doens't completely solve the problem, but only mitigates it slightly. So perhaps instead of vulnerable and not vulnerable which I concede is misleading in the advisory, less susceptible and more susceptible? >I don't deny there is a "problem", but i think at the point this becomes >a problem, it's mostly null and void. This is mostly a philosophical argument for fixing most "weaknesses". This will always depend on the particular attack tree of potential exploits an attacker will follow to get to what he wants. Assuming he's good, then fixing one of several weaknesses in software may just stall the inevitable. However, thwarting other less-skilled attackers and script kiddies with these fixes is worth something I believe, rather than dismissing them as non issues. I think the topic has probably been beaten to death by now, I'd be glad to continue this conversation further offline. - -dave -----BEGIN PGP SIGNATURE----- Version: PGP 8.0 Comment: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE4A96E4F iQA/AwUBPjqOLUrdNYRLCswqEQLnlgCeISpXTQK50g42M5sfV9jTMxwbj+4AnjRZ 9X7tp11A4vxK1e3J42z2FISa =vMjF -----END PGP SIGNATURE-----