-
Notifications
You must be signed in to change notification settings - Fork 258
CVE-2016-2049 #128
Comments
|
copy of what I have sent on the oss list:
i have marked debian as not vulnerable to this, but it is true the sample code here should be updated to use a better |
Yes.
Nathaniel and I made this report after finding this specific exploit in a valuable service. I haven't yet asked for permission to publish what this service is. This server ran Apache and used php-openid in the default configuration. I did some research via google, finding a couple of servers that followed the same pattern. I talked to some friends who run php-openid services and I could find only a few who both used php-openid and didn't base their configuration off the example. From this sample, I made the assumption that most were using the example as a base for their configurations.
I'm not sure what this has to do with Debian? I posted on oss-security because this is an open source piece of software. Additionally, this bug is not the |
|
On 2016-02-05 15:50:19, Zemnmez wrote:
It would be good to have more information on that.
If you know of other software that do the same mistake, it would be good
Well, I am doing triage work for the security team there, to try to
That seems perfectly appropriate.
... which is derived from the Host header. Or did I misunderstand? A.Every one of us is, in the cosmic perspective, precious. If a human |
|
also, so you have patches or suggestions for fixes? |
This is my first time reporting an issue in an open source piece of software I haven't contacted the vendor directly to resolve, I'm not sure what the best way to go about finding and helping these people is.
No, this is correct. Somehow I missed the latter part of your comment. Honestly, I'm not sure. I assume the HTTP service I was testing this against did not enforce a 'correct' host header, and instead was serving the php files to any origin (that's a flawed configuration because of DNS rebinding anyway...).
One of the people I talked to was worried initially then said that since the library they had used has asked them specifically not to use I think a good approach might be to strongly instruct users not to use |
|
On 2016-02-05 16:11:23, Zemnmez wrote:
You're doing a great job at it. :) Providing ways to reproduce the issue In general, it is considered good practice to contact the maintainers
It's possible! If there's only one virtual host on the machine, this
thanks for the suggestions. a. Conformity-the natural instinct to passively yield to that vague something |
(http://seclists.org/oss-sec/2016/q1/185)
The text was updated successfully, but these errors were encountered: