| |
  |
| Serious SOAP::Lite Security Hole Discovered |
|
 |
|
|

|
|
Serious SOAP::Lite Security Hole Discovered
|
Log in/Create an Account
| Top
| 20 comments
|
Search Discussion
|
|
|
|
The Fine Print:
The following comments are owned by whoever posted them.
We are not responsible for them in any way.
|
 |
|
 |
 |
|
 |
 |
 |
I would like to urge anyone with a few spare tuits to get get on the soap-lite [perl.org] mailing list, download a copy of the latest sources [soaplite.com] and have a crack at this thing. SOAP and SOAP::Lite are both very popular and used by many people and Companies. Paul has done lots and lots of great work by providing us with SOAP::Lite, lets give him some help as a community.
Thanks to the wonders of wireless, I'm downloading the source from the "throne" right now. I urge you all to do the same.
Casey West
|
|
 |
 |
|
|
[ Reply to This
]
|
| Re:Calling all programmers.
by barryp
(Score:2)
2002.04.09 3:34 | |
|
|
[ Reply to This
]
|
| Re:XMLRPC::Lite, possibly Frontier::RPC
by rjray
(Score:2)
2002.04.09 13:55 | |
|
|
[ Reply to This
]
|
| | |
|
|
[ Reply to This
]
|
|
 |
|
 |
 |
|
 |
 |
 |
Of course that leads into the discussion about how CPAN is a relative anarchy. SOAP::Lite is a namespace that pavel has registered and "owns". I've never seen anything that says there's a
requirement that you have to maintain your code well to get a namespace registraion and upload it to CPAN. Personally, I'd love to see a tiered structure, as has been previously proposes, with "standard" modules that are maintained and managed as a standard library, "optional" modules with a refereed namespace and some level of QA and then the third tier free for all, which we all know and love. But yeah, we need a more general way for dealing with major security holes in popular modules.
|
|
 |
 |
|
|
[ Reply to This
|
Parent
]
|
| Re:SOAP::Lite
by jjohn
(Score:1)
2002.04.10 10:34
 |
|
 |
 |
|
 |
 |
 |
> but I'm astonished at Kulchenko (the SOAP::Lite author) for letting this one happen. I'm with you. I'm also astonished to find that it happened.
> CHECK THAT IT IS IN THAT FORMAT, FOR CHRISSAKES! It's expected to be in that format. The reason for the problem is that method name wasn't verified against list of allowed methods when *class name is on the list of allowed classes*.
> MONTHS after this was mentioned in Phrack Do you read Phrack daily? I don't read it at all. Randall brought it to my attention some time ago, and I was surprised to find later that it was discussed on perlmonks and nobody told me about that discussion. Unfortunaty with my schedule I'm only an occasional reader of use.perl, perlmonks and other perl sites.
> and ownership gets transferred immediately to someone else Even though there is no such procedure, I wouldn't mind to know more about the person who would like to take this ownership.
I'm not trying to downplay the issue. It's my fault. In addition to that, it's probably the worse time for releasing a new version: I'm moving and have all my computers packed and shipped. I do have copies and repository with me, however I don't have my testing environment and only sporadic online access in my hotel. Still I plan to release bugfix by the next week. If you don't think it's reasonable, let me know.
Best wishes, Paul.
|
|
 |
 |
|
|
[ Reply to This
|
Parent
]
|
|
|
 |
|
 |
 |
|
 |
 |
 |
Last I heard Paul had a patch ready to go for the next release.
And while I'm posting mad, anyone that thought it was secure to run a public SOAP service on the Internet should get off the pipe. Villifying Paul for the total lack of security in SOAP is not cool. Yeah, sure, it was a bug in his code but everybody's code has bugs. If SOAP had a real security layer this kind of thing would be much less likely.
-sam
|
|
 |
 |
|
|
[ Reply to This
]
|
| Re:This is news?
by koschei
(Score:1)
2002.04.10 0:24Re:This is news?
by samtregar
(Score:3)
2002.04.10 1:29Re:This is news?
by koschei
(Score:1)
2002.04.10 1:39Likewise named code on CPAN
by 2shortplanks
(Score:2)
2002.04.10 4:09Re:Likewise named code on CPAN
by wickline
(Score:2)
2002.04.10 6:31Re:Likewise named code on CPAN
by koschei
(Score:2)
2002.04.10 8:48Re:Likewise named code on CPAN
by hfb
(Score:2)
2002.04.10 13:52 Re:Likewise named code on CPAN
by 2shortplanks
(Score:2)
2002.04.11 4:05 Re:This is news?
by belg4mit
(Score:2)
2002.04.11 11:40 |
|