Teo de Raadt pakkus vÀlja muudatused, et piirata juurdepÀÀsu FS-ile openat funktsiooni kaudu

Theo de Raadt suggested including a new mechanism in OpenBSD to reduce the attack surface, implemented through the enhanced capabilities of the openat system call. Patches implementing additional flags for openat and open, which restrict the ability to traverse to upper directories via "../" and access absolute paths, have been prepared for the kernel, libc, and some applications from the base system. The changes are not yet included in OpenBSD-current and are under discussion among developers.

The family of openat(2) system calls works as an analogue of open(2), except that if a relative path is specified in the "path" parameter, the opened file is determined relative to the directory associated with the file descriptor "fd", rather than the current working directory. If an absolute path is passed to openat, for example: int dirfd = open("/tmp", O_RDONLY | O_DIRECTORY); int hfd = openat(dirfd, "/etc/hosts", O_RDONLY);

the openat() function will ignore "dirfd", and as a result, the absolute path will be processed in the usual way.

Therefore, replacing open() with openat() does not enhance program security by itself. Such a call may speed up path parsing but does not restrict access to the filesystem. Flags that prohibit absolute paths (for example, RESOLVE_BENEATH and/or RESOLVE_IN_ROOT for openat2 in Linux) do not guarantee protection: the programmer must add them to all relevant calls, and if the process control is compromised, the attacker may take advantage of other methods to open files.

During the work on the openrsync utility, Theo found a need to limit its ability to traverse the filesystem, but doing so with the unveil() and pledge() functions proved impossible. Thus, the idea of a mechanism similar to openat() arose, but with security properties that complement pledge/unveil or even work in their absence.

PĂ”hiteema on teha piirangutest osa ka katalooge kirjeldavatest deskriptoritest. Selleks on pakutud vĂ€lja lipp F_BELOW, mille saab mÀÀrata lĂ€bi fcntl() vĂ”i lipp O_BELOW funktsiooni open() jaoks. Piiratud deskriptor «dirfd» lubab ainult liikuda allapoole kataloogipuus: kutsed openat() absoluutse tee vĂ”i tagasi ĂŒles «..» saavad lĂ”petamise vea ENOENT. RĂŒnnaku korral, mis viib koodi kĂ€ivitamiseni, sisaldab protsessi failides deskriptorite tabel vĂ€hem funktsionaalseid «dirfd», mis piirab rĂŒnnaku pinda.

Allikas: opennet.ru

Osta usaldusvÀÀrne veebimajutus DDoS-kaitsega veebisaitidele, VPS VDS serverid đŸ”„ Osta usaldusvÀÀrne veebimajutus DDoS-kaitsega veebisaitidele, VPS VDS serverid - ProHoster