Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Wed, 4 Mar 2009 17:30:33 -0500
From: "Michael K. Johnson" <johnsonm@...th.com>
To: oss-security@...ts.openwall.com
Subject: lxc-sshd security issues?

I have not received any response to this query upstream, and I
was wondering if anyone else has noticed this issue, and if so,
if they have any plans with regard to it.  rPath isn't shipping
lxc at this point, so we have no plans for a security advisory.
But does pre-configured account information including root and
user passwords bother anyone else here?

----- Forwarded message from "Michael K. Johnson" <johnsonm@...th.com> -----

Date: Thu, 12 Feb 2009 14:49:45 -0500
From: "Michael K. Johnson" <johnsonm@...th.com>
To: legoater@...e.fr
Subject: lxc-sshd security issues?

I'm guessing, from the contents of the tarball in lxc-sshd, that
you might be responsible for building lxc-sshd.

I noticed three potential security issues while briefly perusing
lxc-sshd:
 o  Pre-packaged host keys instead of generating unique host keys
    within the script or optionally copying the host keys from
    the system on which you are running lxc-sshd
 o  Pre-packaged root password instead of setting it in the script
 o  Pre-packaged legoater password ditto

Obviously, the pre-packaged passwords are a potential security
risk for you if you are using those passwords anywhere, and
could also be considered to be "back doors" if they actually
enable any access by default.

I haven't tested any of that -- it just seemed odd while
inspecting the tarball contents.

In addition, I noticed /root/.bash_history was packaged in the
tarball, which I am guessing was not intended.

----- End forwarded message -----

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux