Sinisterly
Does this look fishy to anyone else? - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: Coding (https://sinister.li/Forum-Coding--71)
+--- Thread: Does this look fishy to anyone else? (/Thread-Does-this-look-fishy-to-anyone-else)



Does this look fishy to anyone else? - Inori - 06-11-2015

I got an offer from Square for being < 1000 on CodeEval, the code I was given is below, and the only instruction was "fill in the vulns". It looks like a *nix-based kind of thing, so can anyone tell me if this is at all sketch? (I went ahead and refactored it)

Code:
# This program encrypts and decrypts messages at the command line. # It runs setuid root, so that it can be used by users without giving # them access to the (root-owned) secret encryption key. require 'openssl' SECRET_KEY="/etc/secrypt.key" OUTPUT_FILE="/tmp/secrypt.out" cipher = OpenSSL::Cipher::Cipher.new('aes-256-ecb') case ARGV.shift when 'encrypt' cipher.encrypt when 'decrypt' cipher.decrypt else puts "Usage:" puts "$0 [encrypt|decrypt] " exit 1 end cipher.key=(File.read(SECRET_KEY)) input = File.open(ARGV.shift) output = File.open(OUTPUT_FILE, "w") input.each_line { |l| output.write(cipher << l) }



RE: Does this look fishy to anyone else? - Reiko - 06-11-2015

This is horrible code. It's using insecure (ECB) mode of encryption and can be used to reveal its own keys, read an arbitrary file (/etc/passwd? /etc/shadow?), write an arbitrary file via symlink (ln -s /etc/cron.d/r00tme /tmp/secrypt.out), and.. I think that's it.
You can absolutely get a root shell from this.


No idea why this uses each_line.. seems like that would be a problem when encrypting binary data.