Security hole discovered in Red Star OS
Summary
In January 2015 security researcher David Jorm found the first hole in North Korea’s Linux distribution Red Star OS 3.0. The udev rules file 85-hplj10xx.rules was writable by all users, so anyone could add a rule with arbitrary commands. udev executed it with root privileges as soon as a matching HP LaserJet printer (or, after adjustment, any USB device) was connected.
Ideas
- A wrongly set file permission was enough for privilege escalation.
- udev executes rules with root privileges when devices are plugged in.
- Connecting a USB device thus becomes the trigger of an attack.
Insights
- Configuration files for root services need as much protection as the programs themselves.
- Even a state-controlled system fails because of basic errors in assigning permissions.
Facts
- The hole was published on the oss-security mailing list.
- The file 85-hplj10xx.rules was affected.
- In Red Star OS 2.0 even the startup script /etc/rc.d/rc.sysinit was writable by everyone.
References
Critique
- The report does not assess whether the errors are negligence or deliberately open access.
Recommendations
- Regularly check that files under /etc are not world-writable, for example with find -perm -o+w.
- Use tools such as AIDE to detect changes to system configurations.
Links to the original source and the Web Archive open in a new tab.