![]() |
|
Does this look fishy to anyone else? - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: Coding (https://sinister.li/Forum-Coding--71) +--- Thread: Does this look fishy to anyone else? (/Thread-Does-this-look-fishy-to-anyone-else) |
Does this look fishy to anyone else? - Inori - 06-11-2015 I got an offer from Square for being < 1000 on CodeEval, the code I was given is below, and the only instruction was "fill in the vulns". It looks like a *nix-based kind of thing, so can anyone tell me if this is at all sketch? (I went ahead and refactored it) Code: # This program encrypts and decrypts messages at the command line.
# It runs setuid root, so that it can be used by users without giving
# them access to the (root-owned) secret encryption key.
require 'openssl'
SECRET_KEY="/etc/secrypt.key"
OUTPUT_FILE="/tmp/secrypt.out"
cipher = OpenSSL::Cipher::Cipher.new('aes-256-ecb')
case ARGV.shift
when 'encrypt'
cipher.encrypt
when 'decrypt'
cipher.decrypt
else
puts "Usage:"
puts "$0 [encrypt|decrypt] "
exit 1
end
cipher.key=(File.read(SECRET_KEY))
input = File.open(ARGV.shift)
output = File.open(OUTPUT_FILE, "w")
input.each_line { |l| output.write(cipher << l) }RE: Does this look fishy to anyone else? - Reiko - 06-11-2015 This is horrible code. It's using insecure (ECB) mode of encryption and can be used to reveal its own keys, read an arbitrary file (/etc/passwd? /etc/shadow?), write an arbitrary file via symlink (ln -s /etc/cron.d/r00tme /tmp/secrypt.out), and.. I think that's it. You can absolutely get a root shell from this. No idea why this uses each_line.. seems like that would be a problem when encrypting binary data. |