Login Register






Does this look fishy to anyone else? filter_list
Author
Message
Does this look fishy to anyone else? #1
I got an offer from Square for being < 1000 on CodeEval, the code I was given is below, and the only instruction was "fill in the vulns". It looks like a *nix-based kind of thing, so can anyone tell me if this is at all sketch? (I went ahead and refactored it)

Code:
# This program encrypts and decrypts messages at the command line. # It runs setuid root, so that it can be used by users without giving # them access to the (root-owned) secret encryption key. require 'openssl' SECRET_KEY="/etc/secrypt.key" OUTPUT_FILE="/tmp/secrypt.out" cipher = OpenSSL::Cipher::Cipher.new('aes-256-ecb') case ARGV.shift when 'encrypt' cipher.encrypt when 'decrypt' cipher.decrypt else puts "Usage:" puts "$0 [encrypt|decrypt] " exit 1 end cipher.key=(File.read(SECRET_KEY)) input = File.open(ARGV.shift) output = File.open(OUTPUT_FILE, "w") input.each_line { |l| output.write(cipher << l) }
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.

Reply

RE: Does this look fishy to anyone else? #2
This is horrible code. It's using insecure (ECB) mode of encryption and can be used to reveal its own keys, read an arbitrary file (/etc/passwd? /etc/shadow?), write an arbitrary file via symlink (ln -s /etc/cron.d/r00tme /tmp/secrypt.out), and.. I think that's it.
You can absolutely get a root shell from this.


No idea why this uses each_line.. seems like that would be a problem when encrypting binary data.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

[+] 1 user Likes Reiko's post
Reply