Re: SUID Perl easy to hack

"Tod D. Ihde" <[email protected]> Fri, 21 Jan 2005 00:21:27 -0600
Newsgroups gmane.mail.neomail.general
Message-ID <[email protected]>
support wrote:
> Hi,
> 
> Warning suidperl is a highly easy and simple hackable exploit.
> 
> You are endangering your server or hosting providers server by 
> installing this perl access.
> 
> We are waiting for neomail to release a secure non hackable (easy hack) 
> version of neomail as we have many clients that like the functions, but 
> since this neomail is on the top of the easy hack to root on a server we 
> cannot use and will not recommend such to any user.
> 
> I hope neomail catches up with the times and patches the easy exploits.
> 
> Richard

Richard,

  A couple of things...

  It's customary when replying to a message that's part of a digest to 
change the subject, so we know what you're replying to.

  The SUID perl exploit you're referring to has been known about (and 
corrected) for 5 years now (unless you're referring to something much 
newer, but I can't be sure, since you failed to cite any reference 
materials). I'm _assuming_ you're talking about this one:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=15630 (sperl 
5.00503) or this one ( 
http://msgs.securepoint.com/cgi-bin/get/bugtraq0008/102.html ) or 
perhaps this one ( http://www.linuxsecurity.com/content/view/102504/111/ 
)... All of those are from 2000.

  There is _always_ a risk when you run SUID software. That's the nature 
of 'set UID', you're trusting that the code you're running is bug free, 
and allowing it to run as someone else.

  I was unable to find _any_ exploit for neomail via google (and I'm 
usually pretty good at research), nor have I ever heard of an exploit 
for neomail. Can you dig up any documentation to back up your claim that 
neomail is insecure? (Yes, passwords are transmitted cleartext, if you 
use http instead of https. That's your fault, not neomail's).

  Neomail does not need SUID perl unless your setup is such that it 
requires it, that's why the install asks if you want it SUID or not. 
Don't like or trust SUID perl? Don't run neomail SUID! Yes, you might 
have to massage your server some to make everything play nice, but 
that's almost always the case when adding non-vendor-supplied software 
to a server (at least, in my experience, YMMV).

The other nice thing about open source is, you don't have to wait - if 
you feel that neomail could be made better, make the changes yourself, 
and you can even send them back upstream to be included in the next version.

  But please, please PLEASE... don't go making (damaging or otherwise) 
claims that you don't (or can't) back up with real data. Please.

Tod.

ps.
  Oh, hi everyone. I've crawled back out of my shell. :)


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl