Security hole in SCP allows files to be swapped
Summary
In January 2019 Harry Sintonen of F-Secure found five holes in the SCP implementations of OpenSSH, PuTTY and WinSCP. SCP does not check whether received files correspond to the requested ones, so a malicious server can swap files or place additional ones unnoticed. This could be used, for example, to replace .bashrc and execute malicious code the next time a program is called.
Ideas
- The client trusted the server with file names and the file list.
- Additionally transferred files could be hidden in the output.
- The permissions of the target folder could also be changed.
- The holes were initially not closed in the stable versions.
Insights
- An old protocol without checking responses turns the server into an attacker.
- Copy tools write foreign file names and need the same care as extractors.
Facts
- The holes carry identifiers including CVE-2018-20685, CVE-2019-6109, CVE-2019-6110 and CVE-2019-6111.
- scp in OpenSSH, pscp in PuTTY and WinSCP were affected.
- Sintonen had already reported the holes in August 2018; OpenSSH 7.9 was affected.
References
Critique
- The report describes the risk but names no workaround such as switching to SFTP.
Remarks
- Since OpenSSH 9.0, scp uses the SFTP protocol by default instead of the old SCP protocol.
Recommendations
- Use sftp or rsync over SSH instead of the classic SCP protocol.
- Only copy from untrusted servers into empty, specially created directories.
Links to the original source and the Web Archive open in a new tab.