{"thread":{"id":"30872","subject":"security flaw with smart http","startedAt":"2012-06-22T10:12:25Z","lastAt":"2012-06-28T07:35:23Z","messageCount":7,"participants":["Ivan Kanis","Shawn Pearce","Junio C Hamano","Philippe Vaucher","Erik Faye-Lund"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"194082","messageId":"87fw9ns0cp.fsf@kanis.fr","threadId":"30872","inReplyTo":null,"subject":"security flaw with smart http","fromName":"Ivan Kanis","fromEmail":"ivan.kanis@googlemail.com","sentAt":"2012-06-22T10:12:25Z","receivedAt":"2012-06-22T10:12:25Z","isPatch":false,"sender":{"key":"ivan.kanis@googlemail.com","avatar":null},"body":"Hi,\n\nI think we found a security flaw with git http smart backend. We are\nrunning git version 1.0.7.4 on our server. Adding random words after the\npassword and the authentication still succeeds. \n\nIt's very easy to reproduce, say the username is ivan and the password\nis the word secret:\n\n% git pull\nUsername: ivan\nPassword: secretfoo\nAlready up to date.\n\nPull succeeds although the password is wrong! Can someone try to\nreproduce with a more up to date git server?\n-- \nIvan Kanis\nhttp://ivan.kanis.fr\n"},{"id":"194084","messageId":"CAJo=hJvCC8_oFFMyc5Fkweg6A6cSV6z+UxeCkvnU34KQfYx91w@mail.gmail.com","threadId":"30872","inReplyTo":"87fw9ns0cp.fsf@kanis.fr","subject":"Re: security flaw with smart http","fromName":"Shawn Pearce","fromEmail":"spearce@spearce.org","sentAt":"2012-06-22T17:54:28Z","receivedAt":"2012-06-22T17:54:28Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:\n> I think we found a security flaw with git http smart backend. We are\n> running git version 1.0.7.4 on our server. Adding random words after the\n> password and the authentication still succeeds.\n\ngit http-backend does not handle authentication or authorization. This\nis handled in your web server. You should consult your web server's\ndocumentation, and maybe its configuration files.\n\n> It's very easy to reproduce, say the username is ivan and the password\n> is the word secret:\n>\n> % git pull\n> Username: ivan\n> Password: secretfoo\n> Already up to date.\n>\n> Pull succeeds although the password is wrong! Can someone try to\n> reproduce with a more up to date git server?\n\nGit is freely available under the GPLv2 license. I believe it is\npossible for you to attempt experiments yourself with more up-to-date\nversions if you wish.\n"},{"id":"194092","messageId":"7vmx3vp2co.fsf@alter.siamese.dyndns.org","threadId":"30872","inReplyTo":"CAJo=hJvCC8_oFFMyc5Fkweg6A6cSV6z+UxeCkvnU34KQfYx91w@mail.gmail.com","subject":"Re: security flaw with smart http","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2012-06-22T19:34:47Z","receivedAt":"2012-06-22T19:34:47Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Shawn Pearce <spearce@spearce.org> writes:\n\n> On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:\n>> I think we found a security flaw with git http smart backend. We are\n>> running git version 1.0.7.4 on our server. Adding random words after the\n>> password and the authentication still succeeds.\n>\n> git http-backend does not handle authentication or authorization. This\n> is handled in your web server. You should consult your web server's\n> documentation, and maybe its configuration files.\n\nVery good advice.\n\n> Git is freely available under the GPLv2 license. I believe it is\n> possible for you to attempt experiments yourself with more up-to-date\n> versions if you wish.\n\nAnd the result is very unlikely to change, if the only change\nbetween the earlier experiment and the next one is the vintage of\nGit used, as the part that makes authentication decision is Ivan's\nwebserver and its configuration, which is not going to change\nbetween the two experiments.\n\nI do not recall ever releasing 1.0.7.4, nor having smart http\nsupport before v1.6.6, by the way.\n"},{"id":"194198","messageId":"CAGK7Mr7_a0V=Tzp9FtTjARsvSn2YOa0_GbydTrsQzxg_MJf=uA@mail.gmail.com","threadId":"30872","inReplyTo":"7vmx3vp2co.fsf@alter.siamese.dyndns.org","subject":"Re: security flaw with smart http","fromName":"Philippe Vaucher","fromEmail":"philippe.vaucher@gmail.com","sentAt":"2012-06-25T11:24:27Z","receivedAt":"2012-06-25T11:24:27Z","isPatch":false,"sender":{"key":"philippe.vaucher@gmail.com","avatar":null},"body":"> I do not recall ever releasing 1.0.7.4, nor having smart http\n> support before v1.6.6, by the way.\n\nIt sounds very likely that he meant 1.7.4 no?\n\nPhilippe\n"},{"id":"194207","messageId":"87ipef5yzr.fsf@visionobjects.com","threadId":"30872","inReplyTo":"CAGK7Mr7_a0V=Tzp9FtTjARsvSn2YOa0_GbydTrsQzxg_MJf=uA@mail.gmail.com","subject":"Re: security flaw with smart http","fromName":"Ivan Kanis","fromEmail":"ivan.kanis@googlemail.com","sentAt":"2012-06-25T12:59:04Z","receivedAt":"2012-06-25T12:59:04Z","isPatch":false,"sender":{"key":"ivan.kanis@googlemail.com","avatar":null},"body":"Philippe Vaucher <philippe.vaucher@gmail.com> a écrit\n\n>> I do not recall ever releasing 1.0.7.4, nor having smart http\n>> support before v1.6.6, by the way.\n>\n> It sounds very likely that he meant 1.7.4 no?\n\nIt's compiled from a 1.7.0.4 tar ball, amusingly git --version says 1.0.7.4\n-- \nIvan Kanis\nhttp://ivan.kanis.fr\n\nPar prêchements, le peuple on peut séduire ;\nPar marchander, tromper on le peut bien ;\nPar plaiderie on peut manger son bien.\n    -- Clément Marot\n"},{"id":"194209","messageId":"CABPQNSYx5cz3ZadenP7xE2+KeQRVqmwq_fehe6tC6vQqyKm_tw@mail.gmail.com","threadId":"30872","inReplyTo":"87ipef5yzr.fsf@visionobjects.com","subject":"Re: security flaw with smart http","fromName":"Erik Faye-Lund","fromEmail":"kusmabite@gmail.com","sentAt":"2012-06-25T13:10:48Z","receivedAt":"2012-06-25T13:10:48Z","isPatch":false,"sender":{"key":"kusmabite@gmail.com","avatar":"https://avatars.githubusercontent.com/u/47073?v=4"},"body":"On Mon, Jun 25, 2012 at 2:59 PM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:\n> Philippe Vaucher <philippe.vaucher@gmail.com> a écrit\n>\n>>> I do not recall ever releasing 1.0.7.4, nor having smart http\n>>> support before v1.6.6, by the way.\n>>\n>> It sounds very likely that he meant 1.7.4 no?\n>\n> It's compiled from a 1.7.0.4 tar ball, amusingly git --version says 1.0.7.4\n\nCould it be that there's a typo in the \"version\"-file of that release?\nAFAICT, the tag at github looks correct (no \"version\"-file, but what's\nin GIT-VERSION-GEN looks correct). Unfortunately, the current official\nrelease-archive at google code\n(http://code.google.com/p/git-core/downloads/list) doesn't contain\nthat particular release, nor does the old official release-archive\n(http://www.kernel.org/pub/software/scm/git/), so it's difficult to\ntell.\n"},{"id":"194405","messageId":"87obo3j3d0.fsf@visionobjects.com","threadId":"30872","inReplyTo":"7vmx3vp2co.fsf@alter.siamese.dyndns.org","subject":"Re: security flaw with smart http","fromName":"Ivan Kanis","fromEmail":"ivan.kanis@googlemail.com","sentAt":"2012-06-28T07:35:23Z","receivedAt":"2012-06-28T07:35:23Z","isPatch":false,"sender":{"key":"ivan.kanis@googlemail.com","avatar":null},"body":"Junio C Hamano <gitster@pobox.com> a écrit\n\n> Shawn Pearce <spearce@spearce.org> writes:\n>\n>> On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:\n>>> I think we found a security flaw with git http smart backend. We are\n>>> running git version 1.0.7.4 on our server. Adding random words after the\n>>> password and the authentication still succeeds.\n>>\n>> git http-backend does not handle authentication or authorization. This\n>> is handled in your web server. You should consult your web server's\n>> documentation, and maybe its configuration files.\n>\n> Very good advice.\n\nIn case someone is reading this thread I confirm the problem comes from\nApache.\n-- \nIvan Kanis, Release Manager, Vision Objects,\n\nLe mal est un mulet : il est opiniâtre et stérile.\n    -- Victor Hugo\n"}]}