Re: XML vulnerability - WARNING - ALL FREENET USERS READ!
Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]> Sun, 9 Aug 2009 01:55:07 +0100
| Newsgroups | gmane.network.freenet.technical |
|---|---|
| Message-ID | <[email protected]> |
On Saturday 08 August 2009 21:12:27 3BUIb3S50i 3BUIb3S50i wrote: > Forwarded from FMS: > > SomeDude@NuBL7aaJ6Cn4fB7GXFb9Zfi8w1FhPyW3oKgU9TweZMw wrote : > > djk@isFiaD04zgAgnrEC5XJt1i4IE7AkNPqhBG5bONi6Yks wrote: > >> cwlrao41@f2qqcdkajvdGGdtRf33S6GfW2dYFMfc4sR6BVPg8vPQ wrote: > >> > >>> SomeDude@NuBL7aaJ6Cn4fB7GXFb9Zfi8w1FhPyW3oKgU9TweZMw wrote : > >>>> cwlrao41@f2qqcdkajvdGGdtRf33S6GfW2dYFMfc4sR6BVPg8vPQ wrote: > >>>>> Is FMS possibly affected by recent XML vulnerability? Does it do XML > >>>>> parsing itself or using some library (maybe statically linked)? > >>>> FMS uses libPoco for XML parsing. What vulnerabilities are you > >>>> referring to? > >>>> > >> > http://tech.slashdot.org/story/09/08/05/1555219/XML-Library-Flaw-mdash-Sun-Apach > >>> e-GNOME-Affected > >>> http://www.cert.fi/en/reports/2009/vulnerability2009085.html > >> Woah! > >> "Vendor Information > >> Python libexpat > >> Apache Xerces, all versions > >> Sun JDK and JRE 6 Update 14 and earlier > >> Sun JDK and JRE 5.0 Update 19 and earlier > >> " > >> Does this really mean that Java code running on these jvms is vulnerable > to > >> remote code execution? > >> > >> Does this impact fred? (kind of doubt it) > >> > > > *> I have done some testing with the type of vulnerability they are talking > > about here. While this particular vulnerability is about DoS and remote > > code execution, the same type of vulnerability can be used to open a > > connection to any computer, and doesn't seem to be limited to the Java > > versions listed above. What I found with my testing wasn't very > > encouraging. > > > > Let me first say that I am using Sun JDK Update 15. I tested 3 Freenet > > apps, jSite (0.7.1), Thaw (0.7.10), and Frost (2009-03-14), to see if > > they are vulnerable specifically to the remote connection type of > > exploit. I had the exploit code connect to a web server on another > > machine and I watched the web log for connections. > > > > I added the exploit code to the jSite config file, started it up, and > > sure enough the exploit code caused a connection to the remote machine. > > Now jSite doesn't do any uploading and downloading of XML files from > > other users, so it's not an immediate threat, but the exploit ability > > remains there. > > > > With Thaw, I exported an index, added the exploit code to it, and > > reimported it. The code was triggered again, and a connection was made > > to the remote machine. This is very serious, as a malicious user could > > add the exploit code to an index and have it executed when another Thaw > > user downloads and parses that index. > > > > In Frost I exported the identity xml file and added the exploit code to > > it. When I imported the file, the code was not executed. I tried > > several different variations of the exploit code, but was unable to get > > Frost to run it. I'm not sure if Frost is using a different XML parser > > than jSite and Thaw, but no matter what I did, I could not get the > > exploit code to run. That's not to say it can't be exploited, just that > > I couldn't find a way to run this particular exploit. > > > > As I mentioned in another message, the XML parser in the Poco library, > > which FMS uses, doesn't seem to parse this type of exploit by default > > either. > > > > It appears that there are XML parsers that are vulnerable and some that > > are not, and due to the nature of this exploit, it would be best to wait > > to hear from the developer of any Freenet applications you use to > > confirm that the exploit doesn't affect them before you run their > > application. This exploit is extremely threatening if you value your > > anonymity. > * > If you have the exploit please email me it so I can test the various plugins that use XML against it. Thanks. _______________________________________________ Tech mailing list [email protected] http://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech
signature.asc
(application/pgp-signature, 835 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAABCAAGBQJKfh5rAAoJEHsvjZi+xPTDkz0P/3Md60PHxR6VcOyRFBP9GDTg Agy+IDPBwuSin46/YR9tqlwweKhFyCG52pXBP/9+ox4ZYIs2vxRQaiE4QZ+G23A/ mskBXOzdHjzKrjqirCl3/versjmEZUm024vlg8NZfkhPl+NTeZJkKREQPJDUL28O nXQZoS6v0HAEDM0gR+kPv9uYGoF8NAKPEu8mCwxzjM6mLPRTJP5RpkcU+oANFWyI ixCyfbh2Tf4j5tZ2m+DZDMp4EGCq3LYKBkq3CHLv0WKCzSr4vB+s84v7OXfDrxzK YY0CA84WCk1dW13VudcK+ZN8tAjygQxSxmgyH5iLOV5+d2XuJTyrfPOhRUq9n2fa AgJY1xcxe1MnaKnWedFDqcovEAG0JVdGAP0f+LUQ5dac7FCIlCopcd1BF/gpJmkB RQQyDzD8LasLyJs5zZf6N9VXtcCQNiVefwRA64RF+RtD63OVrPYyeM3EhdW2NGuF ObuD55MJyFTzIRl8HRh/VEc5f68NIVudQYH8dvCRD4FxDccxLiYogyufOcNFTMn9 8b9pdR00p0pMnrCd8sOW98nhxmas15WiGr+VBHN7tWO9lGxi8ELUaWCqOWpf4WQf Wks6FuY8fEIyFHJ7lB5Y+lV7dw+FgecftaEzonkQYrRMf8Do/BMr5a0QTDpwoZRT pH+QYROhCGr7O2OCeuzB =UMGF -----END PGP SIGNATURE-----