{"thread":{"id":"35202","subject":"GIT Hooks and security","startedAt":"2013-10-25T22:02:34Z","lastAt":"2013-10-26T09:39:48Z","messageCount":6,"participants":["Olivier Revollat","Junio C Hamano","Bryan Turner","Ondřej Bílka"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"229531","messageId":"CA+nXgrUZk=_wtQ2yQnxwCZ3Mazdz=ZH2FJV+V92PVa0a4+A1hQ@mail.gmail.com","threadId":"35202","inReplyTo":null,"subject":"GIT Hooks and security","fromName":"Olivier Revollat","fromEmail":"revollat@gmail.com","sentAt":"2013-10-25T22:02:34Z","receivedAt":"2013-10-25T22:02:34Z","isPatch":false,"sender":{"key":"revollat@gmail.com","avatar":"https://gravatar.com/avatar/f1f637ea9da23526b60f065d41510fc8ea161cb3dab1a45da5263d6ce9bbde95?d=mp&s=160"},"body":"I was wondering : What if I had a \"malicious\" GIT repository who can\n\"inject\" code  via git hooks mechanism : someone clone my repo and\nsome malicious code is executed when a certain GIT hook is triggered\n(for example on commit (\"prepare-commit-msg' hook)) ? What if I email\n/etc/passwd for exemple ?\n\nDoes GIT's hooks security is assured by the GIT user privileges ? but\ngit user can still read /etc/passwd and make something fun with it :)\n\nIs it by the trust relationship ? I mean, If I clone a repo, I\ncertainly knew the source and I trusted it ... isn't it ?\nBut if I have a website with file injection vulnerability and I can\nreplace the git hook script with another (malicious) content ...\n\nI'm maybe \"paranoid\" :) but I'm just asking the question ... just for\nmy curiosity's sake :)\n\nThanks for your comments and explanations :)\n\n-- \n\nMathematics is made of 50 percent formulas, 50 percent proofs, and 50\npercent imagination.\n"},{"id":"229532","messageId":"xmqqwql1hub6.fsf@gitster.dls.corp.google.com","threadId":"35202","inReplyTo":"CA+nXgrUZk=_wtQ2yQnxwCZ3Mazdz=ZH2FJV+V92PVa0a4+A1hQ@mail.gmail.com","subject":"Re: GIT Hooks and security","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-10-25T22:14:37Z","receivedAt":"2013-10-25T22:14:37Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Olivier Revollat <revollat@gmail.com> writes:\n\n> I was wondering : What if I had a \"malicious\" GIT repository who can\n> \"inject\" code  via git hooks mechanism : someone clone my repo and\n> some malicious code is executed when a certain GIT hook is triggered\n> (for example on commit (\"prepare-commit-msg' hook))\n\nIn that somebody else's clone, you will not have _your_ malicious\nhook installed, unless that cloner explicitly does something stupid,\nlike copying that malicious hook.\n"},{"id":"229533","messageId":"CA+nXgrUcpfya+rTPzfRafzJbK1khNqtz-HsaKeGfdA86AepKEg@mail.gmail.com","threadId":"35202","inReplyTo":"xmqqwql1hub6.fsf@gitster.dls.corp.google.com","subject":"Re: GIT Hooks and security","fromName":"Olivier Revollat","fromEmail":"revollat@gmail.com","sentAt":"2013-10-25T22:25:04Z","receivedAt":"2013-10-25T22:25:04Z","isPatch":false,"sender":{"key":"revollat@gmail.com","avatar":"https://gravatar.com/avatar/f1f637ea9da23526b60f065d41510fc8ea161cb3dab1a45da5263d6ce9bbde95?d=mp&s=160"},"body":"But when someone do a \"clone\" he don't have .git/hooks directory\ndownloaded to his local computer ? I thought so ...\n\n2013/10/26 Junio C Hamano <gitster@pobox.com>:\n> Olivier Revollat <revollat@gmail.com> writes:\n>\n>> I was wondering : What if I had a \"malicious\" GIT repository who can\n>> \"inject\" code  via git hooks mechanism : someone clone my repo and\n>> some malicious code is executed when a certain GIT hook is triggered\n>> (for example on commit (\"prepare-commit-msg' hook))\n>\n> In that somebody else's clone, you will not have _your_ malicious\n> hook installed, unless that cloner explicitly does something stupid,\n> like copying that malicious hook.\n\n\n\n-- \nMathematics is made of 50 percent formulas, 50 percent proofs, and 50\npercent imagination.\n"},{"id":"229539","messageId":"CAGyf7-HCEQy2hUnc6UvABDrwYatoUEiPnpXo-e9_8wtbhvN0mw@mail.gmail.com","threadId":"35202","inReplyTo":"CA+nXgrUcpfya+rTPzfRafzJbK1khNqtz-HsaKeGfdA86AepKEg@mail.gmail.com","subject":"Re: GIT Hooks and security","fromName":"Bryan Turner","fromEmail":"bturner@atlassian.com","sentAt":"2013-10-26T00:17:33Z","receivedAt":"2013-10-26T00:17:33Z","isPatch":false,"sender":{"key":"bturner@atlassian.com","avatar":"https://gravatar.com/avatar/16bcf3167981c1ef7c804e502642366d888a35b0d0b0a4ca01fdc442aa1acb1e?d=mp&s=160"},"body":"No, the .git/hooks directory in your clone is created from your local\ntemplates, installed with your Git distribution, not the remote hooks.\nOn Linux distributions, these templates are often in someplace like\n/usr/share/git-core/templates (for normal packages), and on Windows\nwith msysgit they are in share\\git-core\\templates under your\ninstallation directory. If you look in this directory you will see a\nhooks directory containing the sample hooks.\n\nHooks from a remote repository are never cloned. As far as I'm aware,\nnothing from the .git directory (aside from refs and packs, of course)\nis cloned, including configuration. Your .git directory after a clone\nis completely new, assembled from scratch. There's nothing in the Git\nwire protocol (currently) for moving other data like configuration or\nhooks, and this sort of malicious code injection is one of the reasons\nI've seen discussed on the list for why that's the case.\n\nHope this helps,\nBryan Turner\n\n\nOn 26 October 2013 09:25, Olivier Revollat <revollat@gmail.com> wrote:\n>\n> But when someone do a \"clone\" he don't have .git/hooks directory\n> downloaded to his local computer ? I thought so ...\n>\n> 2013/10/26 Junio C Hamano <gitster@pobox.com>:\n> > Olivier Revollat <revollat@gmail.com> writes:\n> >\n> >> I was wondering : What if I had a \"malicious\" GIT repository who can\n> >> \"inject\" code  via git hooks mechanism : someone clone my repo and\n> >> some malicious code is executed when a certain GIT hook is triggered\n> >> (for example on commit (\"prepare-commit-msg' hook))\n> >\n> > In that somebody else's clone, you will not have _your_ malicious\n> > hook installed, unless that cloner explicitly does something stupid,\n> > like copying that malicious hook.\n>\n>\n>\n> --\n> Mathematics is made of 50 percent formulas, 50 percent proofs, and 50\n> percent imagination.\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n"},{"id":"229557","messageId":"CA+nXgrWBue1A9KBXaRwRPi7qFNsrz8CnoyLrdhbALeo=7xborQ@mail.gmail.com","threadId":"35202","inReplyTo":"CAGyf7-HCEQy2hUnc6UvABDrwYatoUEiPnpXo-e9_8wtbhvN0mw@mail.gmail.com","subject":"Re: GIT Hooks and security","fromName":"Olivier Revollat","fromEmail":"revollat@gmail.com","sentAt":"2013-10-26T09:27:28Z","receivedAt":"2013-10-26T09:27:28Z","isPatch":false,"sender":{"key":"revollat@gmail.com","avatar":"https://gravatar.com/avatar/f1f637ea9da23526b60f065d41510fc8ea161cb3dab1a45da5263d6ce9bbde95?d=mp&s=160"},"body":"Very helpful :) thanks !\n\n2013/10/26 Bryan Turner <bturner@atlassian.com>:\n> No, the .git/hooks directory in your clone is created from your local\n> templates, installed with your Git distribution, not the remote hooks.\n> On Linux distributions, these templates are often in someplace like\n> /usr/share/git-core/templates (for normal packages), and on Windows\n> with msysgit they are in share\\git-core\\templates under your\n> installation directory. If you look in this directory you will see a\n> hooks directory containing the sample hooks.\n>\n> Hooks from a remote repository are never cloned. As far as I'm aware,\n> nothing from the .git directory (aside from refs and packs, of course)\n> is cloned, including configuration. Your .git directory after a clone\n> is completely new, assembled from scratch. There's nothing in the Git\n> wire protocol (currently) for moving other data like configuration or\n> hooks, and this sort of malicious code injection is one of the reasons\n> I've seen discussed on the list for why that's the case.\n>\n> Hope this helps,\n> Bryan Turner\n>\n>\n> On 26 October 2013 09:25, Olivier Revollat <revollat@gmail.com> wrote:\n>>\n>> But when someone do a \"clone\" he don't have .git/hooks directory\n>> downloaded to his local computer ? I thought so ...\n>>\n>> 2013/10/26 Junio C Hamano <gitster@pobox.com>:\n>> > Olivier Revollat <revollat@gmail.com> writes:\n>> >\n>> >> I was wondering : What if I had a \"malicious\" GIT repository who can\n>> >> \"inject\" code  via git hooks mechanism : someone clone my repo and\n>> >> some malicious code is executed when a certain GIT hook is triggered\n>> >> (for example on commit (\"prepare-commit-msg' hook))\n>> >\n>> > In that somebody else's clone, you will not have _your_ malicious\n>> > hook installed, unless that cloner explicitly does something stupid,\n>> > like copying that malicious hook.\n>>\n>>\n>>\n>> --\n>> Mathematics is made of 50 percent formulas, 50 percent proofs, and 50\n>> percent imagination.\n>> --\n>> To unsubscribe from this list: send the line \"unsubscribe git\" in\n>> the body of a message to majordomo@vger.kernel.org\n>> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n\n\n\n-- \nMathematics is made of 50 percent formulas, 50 percent proofs, and 50\npercent imagination.\n"},{"id":"229558","messageId":"20131026093948.GA17645@domone.podge","threadId":"35202","inReplyTo":"CA+nXgrWBue1A9KBXaRwRPi7qFNsrz8CnoyLrdhbALeo=7xborQ@mail.gmail.com","subject":"Re: GIT Hooks and security","fromName":"Ondřej Bílka","fromEmail":"neleai@seznam.cz","sentAt":"2013-10-26T09:39:48Z","receivedAt":"2013-10-26T09:39:48Z","isPatch":false,"sender":{"key":"neleai@seznam.cz","avatar":"https://avatars.githubusercontent.com/u/48067?v=4"},"body":"> 2013/10/26 Bryan Turner <bturner@atlassian.com>:\n> > No, the .git/hooks directory in your clone is created from your local\n> > templates, installed with your Git distribution, not the remote hooks.\n> > On Linux distributions, these templates are often in someplace like\n> > /usr/share/git-core/templates (for normal packages), and on Windows\n> > with msysgit they are in share\\git-core\\templates under your\n> > installation directory. If you look in this directory you will see a\n> > hooks directory containing the sample hooks.\n> >\n> > Hooks from a remote repository are never cloned. As far as I'm aware,\n> > nothing from the .git directory (aside from refs and packs, of course)\n> > is cloned, including configuration. Your .git directory after a clone\n> > is completely new, assembled from scratch. There's nothing in the Git\n> > wire protocol (currently) for moving other data like configuration or\n> > hooks, and this sort of malicious code injection is one of the reasons\n> > I've seen discussed on the list for why that's the case.\n> >\n> > Hope this helps,\n> > Bryan Turner\n> >\n> >\n> > On 26 October 2013 09:25, Olivier Revollat <revollat@gmail.com> wrote:\n> >>\n> >> But when someone do a \"clone\" he don't have .git/hooks directory\n> >> downloaded to his local computer ? I thought so ...\n> >>\n> >> 2013/10/26 Junio C Hamano <gitster@pobox.com>:\n> >> > Olivier Revollat <revollat@gmail.com> writes:\n> >> >\n> >> >> I was wondering : What if I had a \"malicious\" GIT repository who can\n> >> >> \"inject\" code  via git hooks mechanism : someone clone my repo and\n> >> >> some malicious code is executed when a certain GIT hook is triggered\n> >> >> (for example on commit (\"prepare-commit-msg' hook))\n> >> >\n> >> > In that somebody else's clone, you will not have _your_ malicious\n> >> > hook installed, unless that cloner explicitly does something stupid,\n> >> > like copying that malicious hook.\n> >>\nAlso copying hooks is relatively low risk, real hackers hide exploits in\n1MB configure scripts.\n"}]}