threads / discuss / 30872

security flaw with smart http

Subject: security flaw with smart http

## tl;dr

7 messages between Jun 22, 2012 and Jun 28, 2012.

replies: 6people: 5as markdown or json

Ivan Kanis· Jun 22, 2012, 10:12 UTC · lore
Hi,

I think we found a security flaw with git http smart backend. We are running git version 1.0.7.4 on our server. Adding random words after the password and the authentication still succeeds.

It's very easy to reproduce, say the username is ivan and the password is the word secret:

% git pull
Username: ivan
Password: secretfoo
Already up to date.

Pull succeeds although the password is wrong! Can someone try to reproduce with a more up to date git server?

-- 
Ivan Kanis
http://ivan.kanis.fr
Shawn Pearce· Jun 22, 2012, 17:54 UTC · re: Ivan Kanis · lore

Re: security flaw with smart http

On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
> I think we found a security flaw with git http smart backend. We are
> running git version 1.0.7.4 on our server. Adding random words after the
> password and the authentication still succeeds.

git http-backend does not handle authentication or authorization. This is handled in your web server. You should consult your web server's documentation, and maybe its configuration files.

Show 10 quoted lines
> It's very easy to reproduce, say the username is ivan and the password
> is the word secret:
>
> % git pull
> Username: ivan
> Password: secretfoo
> Already up to date.
>
> Pull succeeds although the password is wrong! Can someone try to
> reproduce with a more up to date git server?

Git is freely available under the GPLv2 license. I believe it is possible for you to attempt experiments yourself with more up-to-date versions if you wish.

Junio C Hamano· Jun 22, 2012, 19:34 UTC · re: Shawn Pearce · lore

Re: security flaw with smart http

Shawn Pearce <spearce@spearce.org> writes:
Show 8 quoted lines
> On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
>> I think we found a security flaw with git http smart backend. We are
>> running git version 1.0.7.4 on our server. Adding random words after the
>> password and the authentication still succeeds.
>
> git http-backend does not handle authentication or authorization. This
> is handled in your web server. You should consult your web server's
> documentation, and maybe its configuration files.
Very good advice.
> Git is freely available under the GPLv2 license. I believe it is
> possible for you to attempt experiments yourself with more up-to-date
> versions if you wish.

And the result is very unlikely to change, if the only change between the earlier experiment and the next one is the vintage of Git used, as the part that makes authentication decision is Ivan's webserver and its configuration, which is not going to change between the two experiments.

I do not recall ever releasing 1.0.7.4, nor having smart http support before v1.6.6, by the way.

Ivan Kanis· Jun 25, 2012, 12:59 UTC · re: Philippe Vaucher · lore

Re: security flaw with smart http

Philippe Vaucher <philippe.vaucher@gmail.com> a écrit
>> I do not recall ever releasing 1.0.7.4, nor having smart http
>> support before v1.6.6, by the way.
>
> It sounds very likely that he meant 1.7.4 no?
It's compiled from a 1.7.0.4 tar ball, amusingly git --version says 1.0.7.4
-- 
Ivan Kanis
http://ivan.kanis.fr

Par prêchements, le peuple on peut séduire ;
Par marchander, tromper on le peut bien ;
Par plaiderie on peut manger son bien.
    -- Clément Marot
Erik Faye-Lund· Jun 25, 2012, 13:10 UTC · re: Ivan Kanis · lore

Re: security flaw with smart http

On Mon, Jun 25, 2012 at 2:59 PM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
Show 8 quoted lines
> Philippe Vaucher <philippe.vaucher@gmail.com> a écrit
>
>>> I do not recall ever releasing 1.0.7.4, nor having smart http
>>> support before v1.6.6, by the way.
>>
>> It sounds very likely that he meant 1.7.4 no?
>
> It's compiled from a 1.7.0.4 tar ball, amusingly git --version says 1.0.7.4

Could it be that there's a typo in the "version"-file of that release? AFAICT, the tag at github looks correct (no "version"-file, but what's in GIT-VERSION-GEN looks correct). Unfortunately, the current official release-archive at google code (http://code.google.com/p/git-core/downloads/list) doesn't contain that particular release, nor does the old official release-archive (http://www.kernel.org/pub/software/scm/git/), so it's difficult to tell.

Ivan Kanis· Jun 28, 2012, 07:35 UTC · re: Junio C Hamano · lore

Re: security flaw with smart http

Junio C Hamano <gitster@pobox.com> a écrit
Show 12 quoted lines
> Shawn Pearce <spearce@spearce.org> writes:
>
>> On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
>>> I think we found a security flaw with git http smart backend. We are
>>> running git version 1.0.7.4 on our server. Adding random words after the
>>> password and the authentication still succeeds.
>>
>> git http-backend does not handle authentication or authorization. This
>> is handled in your web server. You should consult your web server's
>> documentation, and maybe its configuration files.
>
> Very good advice.

In case someone is reading this thread I confirm the problem comes from Apache.

-- 
Ivan Kanis, Release Manager, Vision Objects,

Le mal est un mulet : il est opiniâtre et stérile.
    -- Victor Hugo

← back to recent threads