security flaw: directory server can escalate read access into write access #187

Closed
opened 2007-10-25 06:47:28 +00:00 by zooko · 2 comments

The current scheme to prevent users who haven't been granted write access from writing updates to directories doesn't prevent the server that hosts the directory from writing to it if the server has been granted read access to the directory.

That is: the intent is that you can grant a person read-only access while withholding read-write access, and this intent works as far as the person doesn't control the directory server, but if you grant read access to the directory server then it can also gain write access, which wasn't intended.

For example, the current test grid is configured so that everyone uses the same directory server (because the vdrive.furl file that you put into your node directory before you launch your node points to that server). If you give one of the allmydata folks a read-only view on a directory of yours, we can use that read access plus our control of the directory server to change the contents of your directory.

The current scheme to prevent users who haven't been granted write access from writing updates to directories doesn't prevent the server that hosts the directory from writing to it if the server has been granted read access to the directory. That is: the intent is that you can grant a person read-only access while withholding read-write access, and this intent works as far as the person doesn't control the directory server, but if you grant read access to the directory server then it can also gain write access, which wasn't intended. For example, the current test grid is configured so that everyone uses the same directory server (because the vdrive.furl file that you put into your node directory before you launch your node points to that server). If you give one of the allmydata folks a read-only view on a directory of yours, we can use that read access plus our control of the directory server to change the contents of your directory.
zooko added the
unknown
critical
defect
0.6.1
labels 2007-10-25 06:47:28 +00:00
Author

[#197 Small Distributed Mutable Files] will fix this. Merging into #197.

[#197 Small Distributed Mutable Files] will fix this. Merging into #197.
zooko added the
duplicate
label 2007-11-01 17:09:48 +00:00
zooko closed this issue 2007-11-01 17:09:48 +00:00
Author

Milestone 0.6.2 deleted

Milestone 0.6.2 deleted
zooko added this to the 0.7.0 milestone 2007-11-01 18:12:49 +00:00
Sign in to join this conversation.
No Milestone
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Reference: tahoe-lafs/trac-2024-07-25#187
No description provided.