Re: XML vulnerability - WARNING - ALL FREENET USERS READ!

Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]> Sun, 9 Aug 2009 01:55:07 +0100
Newsgroups gmane.network.freenet.technical
Message-ID <[email protected]>
On Saturday 08 August 2009 21:12:27 3BUIb3S50i 3BUIb3S50i wrote:
> Forwarded from FMS:
> 
> SomeDude@NuBL7aaJ6Cn4fB7GXFb9Zfi8w1FhPyW3oKgU9TweZMw wrote :
> > djk@isFiaD04zgAgnrEC5XJt1i4IE7AkNPqhBG5bONi6Yks wrote:
> >> cwlrao41@f2qqcdkajvdGGdtRf33S6GfW2dYFMfc4sR6BVPg8vPQ wrote:
> >>
> >>> SomeDude@NuBL7aaJ6Cn4fB7GXFb9Zfi8w1FhPyW3oKgU9TweZMw wrote :
> >>>> cwlrao41@f2qqcdkajvdGGdtRf33S6GfW2dYFMfc4sR6BVPg8vPQ wrote:
> >>>>> Is FMS possibly affected by recent XML vulnerability? Does it do XML
> >>>>> parsing itself or using some library (maybe statically linked)?
> >>>> FMS uses libPoco for XML parsing.  What vulnerabilities are you
> >>>> referring to?
> >>>>
> >>
> http://tech.slashdot.org/story/09/08/05/1555219/XML-Library-Flaw-mdash-Sun-Apach
> >>> e-GNOME-Affected
> >>> http://www.cert.fi/en/reports/2009/vulnerability2009085.html
> >> Woah!
> >> "Vendor Information
> >> Python libexpat
> >> Apache Xerces, all versions
> >> Sun JDK and JRE 6 Update 14 and earlier
> >> Sun JDK and JRE 5.0 Update 19 and earlier
> >> "
> >> Does this really mean that Java code running on these jvms is vulnerable
> to
> >> remote code execution?
> >>
> >> Does this impact fred? (kind of doubt it)
> >>
> >
> *> I have done some testing with the type of vulnerability they are talking
> > about here.  While this particular vulnerability is about DoS and remote
> > code execution, the same type of vulnerability can be used to open a
> > connection to any computer, and doesn't seem to be limited to the Java
> > versions listed above.  What I found with my testing wasn't very
> > encouraging.
> >
> > Let me first say that I am using Sun JDK Update 15.  I tested 3 Freenet
> > apps, jSite (0.7.1), Thaw (0.7.10), and Frost (2009-03-14), to see if
> > they are vulnerable specifically to the remote connection type of
> > exploit.  I had the exploit code connect to a web server on another
> > machine and I watched the web log for connections.
> >
> > I added the exploit code to the jSite config file, started it up, and
> > sure enough the exploit code caused a connection to the remote machine.
> >   Now jSite doesn't do any uploading and downloading of XML files from
> > other users, so it's not an immediate threat, but the exploit ability
> > remains there.
> >
> > With Thaw, I exported an index, added the exploit code to it, and
> > reimported it.  The code was triggered again, and a connection was made
> > to the remote machine.  This is very serious, as a malicious user could
> > add the exploit code to an index and have it executed when another Thaw
> > user downloads and parses that index.
> >
> > In Frost I exported the identity xml file and added the exploit code to
> > it.  When I imported the file, the code was not executed.  I tried
> > several different variations of the exploit code, but was unable to get
> > Frost to run it.  I'm not sure if Frost is using a different XML parser
> > than jSite and Thaw, but no matter what I did, I could not get the
> > exploit code to run.  That's not to say it can't be exploited, just that
> > I couldn't find a way to run this particular exploit.
> >
> > As I mentioned in another message, the XML parser in the Poco library,
> > which FMS uses, doesn't seem to parse this type of exploit by default
> > either.
> >
> > It appears that there are XML parsers that are vulnerable and some that
> > are not, and due to the nature of this exploit, it would be best to wait
> > to hear from the developer of any Freenet applications you use to
> > confirm that the exploit doesn't affect them before you run their
> > application.  This exploit is extremely threatening if you value your
> > anonymity.
> *
> 
If you have the exploit please email me it so I can test the various plugins that use XML against it. Thanks.

_______________________________________________
Tech mailing list
[email protected]
http://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech
signature.asc (application/pgp-signature, 835 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iQIcBAABCAAGBQJKfh5rAAoJEHsvjZi+xPTDkz0P/3Md60PHxR6VcOyRFBP9GDTg
Agy+IDPBwuSin46/YR9tqlwweKhFyCG52pXBP/9+ox4ZYIs2vxRQaiE4QZ+G23A/
mskBXOzdHjzKrjqirCl3/versjmEZUm024vlg8NZfkhPl+NTeZJkKREQPJDUL28O
nXQZoS6v0HAEDM0gR+kPv9uYGoF8NAKPEu8mCwxzjM6mLPRTJP5RpkcU+oANFWyI
ixCyfbh2Tf4j5tZ2m+DZDMp4EGCq3LYKBkq3CHLv0WKCzSr4vB+s84v7OXfDrxzK
YY0CA84WCk1dW13VudcK+ZN8tAjygQxSxmgyH5iLOV5+d2XuJTyrfPOhRUq9n2fa
AgJY1xcxe1MnaKnWedFDqcovEAG0JVdGAP0f+LUQ5dac7FCIlCopcd1BF/gpJmkB
RQQyDzD8LasLyJs5zZf6N9VXtcCQNiVefwRA64RF+RtD63OVrPYyeM3EhdW2NGuF
ObuD55MJyFTzIRl8HRh/VEc5f68NIVudQYH8dvCRD4FxDccxLiYogyufOcNFTMn9
8b9pdR00p0pMnrCd8sOW98nhxmas15WiGr+VBHN7tWO9lGxi8ELUaWCqOWpf4WQf
Wks6FuY8fEIyFHJ7lB5Y+lV7dw+FgecftaEzonkQYrRMf8Do/BMr5a0QTDpwoZRT
pH+QYROhCGr7O2OCeuzB
=UMGF
-----END PGP SIGNATURE-----