Alvaro Lopez Ortega dijo [Fri, Sep 26, 2008 at 07:18:17PM +0200]:
> ===================================
> Cherokee 0.9.0 "T.N.T." released!
> ===================================
Congratulations! :-) And I managed to upload 0.8.1-1 just in time not
to be an old version, more or less at the same time ;-)
Anyway - There is an issue I want to check with the group before
uploading 0.9.0, as it worries me a bit.
Up until now (as far as I gan tell from the behaviour, I'm not
referring to the source for details), I think the (grossly simplified)
startup process of Cherokee was:
1- Come to live
2- Open logfiles
3- Drop privileges
4- Open a socket, sit and wait for connections
If I get it correctly, 0.9 has reversed 2 and 3. Why? Because up to
now, Cherokee (as shippped in Debian) produced root-owned
/var/log/cherokee/cherokee.{access,error}. I just packaged (didn't yet
upload) 0.9, and... it fails to start:
0 [EMAIL PROTECTED]/home/gwolf# cherokee
Couldn't open '/var/log/cherokee/cherokee.access' for appending
2 [EMAIL PROTECTED]/home/gwolf# ls -l /var/log/cherokee/cherokee.*
-rw-r--r-- 1 root root 1143 2008-09-26 14:11 /var/log/cherokee/cherokee.access
-rw-r--r-- 1 root root 388 2008-09-26 14:11 /var/log/cherokee/cherokee.error
Note that both files _do_ have contents - as Cherokee <= 0.8 can
successfully write into them.
I quickly checked this with Alvaro by chat, but it's late in Spain
(and sleeping 8 hours a day is more important to Alvaro than this poor
ol' indian boy! ;-) ), he basically told me this change was due to
consensus as there was a bug report on it. I didn't check whether this
was a security- or functionality-related bug report, anyway.
Now thinking on possible scenarios: Opening the log file with root
privileges does expose us (at a single point, though, in the program's
life) to a symlink attack - If somebody symlinks
/var/log/cherokee/cherokee.access to, say, /lib/libc.so.6, we can very
easily clobber that file and render our system useless. But still, the
attacker must already have root privileges in order to do this! (of
course, we _are_ checking file ownership before writing, right?)
On the other hand, if we make the log files writable by the webserver
user (in my case, www-data), any user who subverts any webapp we are
running will be able to modify (or completely clobber) the log files,
probably hiding forever any traces on how he got in.
So... Please comment on this. I will not yet upload 0.9 to Debian, but
besides this point, it's practically ready to be sent.
Thanks!
--
Gunnar Wolf - [EMAIL PROTECTED] - (+52-55)5623-0154 / 1451-2244
PGP key 1024D/8BB527AF 2001-10-23
Fingerprint: 0C79 D2D1 2C4E 9CE4 5973 F800 D80E F35A 8BB5 27AF
_______________________________________________
Cherokee mailing list
[email protected]
http://lists.octality.com/listinfo/cherokee