# security flaw with smart http

7 messages from 2012-06-22 to 2012-06-28. Participants: Ivan Kanis, Shawn Pearce, Junio C Hamano, Philippe Vaucher, Erik Faye-Lund.
Thread: https://gitlist.dev/t/30872

## Ivan Kanis, 2012-06-22 10:12

Subject: security flaw with smart http
Message-ID: <87fw9ns0cp.fsf@kanis.fr>
URL: https://gitlist.dev/e/87fw9ns0cp.fsf%40kanis.fr

```
Hi,

I think we found a security flaw with git http smart backend. We are
running git version 1.0.7.4 on our server. Adding random words after the
password and the authentication still succeeds. 

It's very easy to reproduce, say the username is ivan and the password
is the word secret:

% git pull
Username: ivan
Password: secretfoo
Already up to date.

Pull succeeds although the password is wrong! Can someone try to
reproduce with a more up to date git server?
-- 
Ivan Kanis
http://ivan.kanis.fr

```

## Shawn Pearce, 2012-06-22 17:54

Subject: Re: security flaw with smart http
Message-ID: <CAJo=hJvCC8_oFFMyc5Fkweg6A6cSV6z+UxeCkvnU34KQfYx91w@mail.gmail.com>
URL: https://gitlist.dev/e/CAJo%3DhJvCC8_oFFMyc5Fkweg6A6cSV6z%2BUxeCkvnU34KQfYx91w%40mail.gmail.com
In-Reply-To: <87fw9ns0cp.fsf@kanis.fr>

```
On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
> I think we found a security flaw with git http smart backend. We are
> running git version 1.0.7.4 on our server. Adding random words after the
> password and the authentication still succeeds.

git http-backend does not handle authentication or authorization. This
is handled in your web server. You should consult your web server's
documentation, and maybe its configuration files.

> It's very easy to reproduce, say the username is ivan and the password
> is the word secret:
>
> % git pull
> Username: ivan
> Password: secretfoo
> Already up to date.
>
> Pull succeeds although the password is wrong! Can someone try to
> reproduce with a more up to date git server?

Git is freely available under the GPLv2 license. I believe it is
possible for you to attempt experiments yourself with more up-to-date
versions if you wish.

```

## Junio C Hamano, 2012-06-22 19:34

Subject: Re: security flaw with smart http
Message-ID: <7vmx3vp2co.fsf@alter.siamese.dyndns.org>
URL: https://gitlist.dev/e/7vmx3vp2co.fsf%40alter.siamese.dyndns.org
In-Reply-To: <CAJo=hJvCC8_oFFMyc5Fkweg6A6cSV6z+UxeCkvnU34KQfYx91w@mail.gmail.com>

```
Shawn Pearce <spearce@spearce.org> writes:

> On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
>> I think we found a security flaw with git http smart backend. We are
>> running git version 1.0.7.4 on our server. Adding random words after the
>> password and the authentication still succeeds.
>
> git http-backend does not handle authentication or authorization. This
> is handled in your web server. You should consult your web server's
> documentation, and maybe its configuration files.

Very good advice.

> Git is freely available under the GPLv2 license. I believe it is
> possible for you to attempt experiments yourself with more up-to-date
> versions if you wish.

And the result is very unlikely to change, if the only change
between the earlier experiment and the next one is the vintage of
Git used, as the part that makes authentication decision is Ivan's
webserver and its configuration, which is not going to change
between the two experiments.

I do not recall ever releasing 1.0.7.4, nor having smart http
support before v1.6.6, by the way.

```

## Philippe Vaucher, 2012-06-25 11:24

Subject: Re: security flaw with smart http
Message-ID: <CAGK7Mr7_a0V=Tzp9FtTjARsvSn2YOa0_GbydTrsQzxg_MJf=uA@mail.gmail.com>
URL: https://gitlist.dev/e/CAGK7Mr7_a0V%3DTzp9FtTjARsvSn2YOa0_GbydTrsQzxg_MJf%3DuA%40mail.gmail.com
In-Reply-To: <7vmx3vp2co.fsf@alter.siamese.dyndns.org>

```
> I do not recall ever releasing 1.0.7.4, nor having smart http
> support before v1.6.6, by the way.

It sounds very likely that he meant 1.7.4 no?

Philippe

```

## Ivan Kanis, 2012-06-25 12:59

Subject: Re: security flaw with smart http
Message-ID: <87ipef5yzr.fsf@visionobjects.com>
URL: https://gitlist.dev/e/87ipef5yzr.fsf%40visionobjects.com
In-Reply-To: <CAGK7Mr7_a0V=Tzp9FtTjARsvSn2YOa0_GbydTrsQzxg_MJf=uA@mail.gmail.com>

```
Philippe Vaucher <philippe.vaucher@gmail.com> a écrit

>> I do not recall ever releasing 1.0.7.4, nor having smart http
>> support before v1.6.6, by the way.
>
> It sounds very likely that he meant 1.7.4 no?

It's compiled from a 1.7.0.4 tar ball, amusingly git --version says 1.0.7.4
-- 
Ivan Kanis
http://ivan.kanis.fr

Par prêchements, le peuple on peut séduire ;
Par marchander, tromper on le peut bien ;
Par plaiderie on peut manger son bien.
    -- Clément Marot

```

## Erik Faye-Lund, 2012-06-25 13:10

Subject: Re: security flaw with smart http
Message-ID: <CABPQNSYx5cz3ZadenP7xE2+KeQRVqmwq_fehe6tC6vQqyKm_tw@mail.gmail.com>
URL: https://gitlist.dev/e/CABPQNSYx5cz3ZadenP7xE2%2BKeQRVqmwq_fehe6tC6vQqyKm_tw%40mail.gmail.com
In-Reply-To: <87ipef5yzr.fsf@visionobjects.com>

```
On Mon, Jun 25, 2012 at 2:59 PM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
> Philippe Vaucher <philippe.vaucher@gmail.com> a écrit
>
>>> I do not recall ever releasing 1.0.7.4, nor having smart http
>>> support before v1.6.6, by the way.
>>
>> It sounds very likely that he meant 1.7.4 no?
>
> It's compiled from a 1.7.0.4 tar ball, amusingly git --version says 1.0.7.4

Could it be that there's a typo in the "version"-file of that release?
AFAICT, the tag at github looks correct (no "version"-file, but what's
in GIT-VERSION-GEN looks correct). Unfortunately, the current official
release-archive at google code
(http://code.google.com/p/git-core/downloads/list) doesn't contain
that particular release, nor does the old official release-archive
(http://www.kernel.org/pub/software/scm/git/), so it's difficult to
tell.

```

## Ivan Kanis, 2012-06-28 07:35

Subject: Re: security flaw with smart http
Message-ID: <87obo3j3d0.fsf@visionobjects.com>
URL: https://gitlist.dev/e/87obo3j3d0.fsf%40visionobjects.com
In-Reply-To: <7vmx3vp2co.fsf@alter.siamese.dyndns.org>

```
Junio C Hamano <gitster@pobox.com> a écrit

> Shawn Pearce <spearce@spearce.org> writes:
>
>> On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote:
>>> I think we found a security flaw with git http smart backend. We are
>>> running git version 1.0.7.4 on our server. Adding random words after the
>>> password and the authentication still succeeds.
>>
>> git http-backend does not handle authentication or authorization. This
>> is handled in your web server. You should consult your web server's
>> documentation, and maybe its configuration files.
>
> Very good advice.

In case someone is reading this thread I confirm the problem comes from
Apache.
-- 
Ivan Kanis, Release Manager, Vision Objects,

Le mal est un mulet : il est opiniâtre et stérile.
    -- Victor Hugo

```
