bk99.de entertain the web since 1997

Security hole in SCP allows files to be swapped

Summary

In January 2019 Harry Sintonen of F-Secure found five holes in the SCP implementations of OpenSSH, PuTTY and WinSCP. SCP does not check whether received files correspond to the requested ones, so a malicious server can swap files or place additional ones unnoticed. This could be used, for example, to replace .bashrc and execute malicious code the next time a program is called.

Ideas

  • The client trusted the server with file names and the file list.
  • Additionally transferred files could be hidden in the output.
  • The permissions of the target folder could also be changed.
  • The holes were initially not closed in the stable versions.

Insights

  • An old protocol without checking responses turns the server into an attacker.
  • Copy tools write foreign file names and need the same care as extractors.

Facts

  • The holes carry identifiers including CVE-2018-20685, CVE-2019-6109, CVE-2019-6110 and CVE-2019-6111.
  • scp in OpenSSH, pscp in PuTTY and WinSCP were affected.
  • Sintonen had already reported the holes in August 2018; OpenSSH 7.9 was affected.

References

Critique

  • The report describes the risk but names no workaround such as switching to SFTP.

Remarks

  • Since OpenSSH 9.0, scp uses the SFTP protocol by default instead of the old SCP protocol.

Recommendations

  • Use sftp or rsync over SSH instead of the classic SCP protocol.
  • Only copy from untrusted servers into empty, specially created directories.

Read the original article

Search the Web Archive