A look in the mirror: attacks on package managers

A look in the mirror: attacks on package managers
复制标题

照照镜子:对包管理器的攻击

DOI:
10.1145/1455770.1455841
复制
发表时间:
2008
期刊:
Proceedings of the 15th ACM conference on Computer and communications security
影响因子:
--
通讯作者:
J. Hartman
J. Hartman
中科院分区:
--
文献类型:
--
作者:
Justin Cappos;Justin Samuel;S. Baker;J. Hartman

文献摘要

被引文献

相似文献

本文研究了10个流行的包管理器的安全性。这些包管理器使用不同的安全机制,提供不同级别的可用性和攻击弹性。我们发现,尽管他们现有的安全机制,所有这些包管理器都有漏洞,可以利用中间人或恶意镜像。虽然所有当前的包管理器都存在漏洞,但它们的安全性也会受到发行版安全实践的积极或消极影响。当发行版使用第三方镜像作为官方镜像时,包管理器的弱点更容易被利用。我们成功地使用了虚假的凭证来获得我们尝试的所有五个发行版的官方镜像。我们还发现,一些控制客户端从何处获取元数据和包的安全机制实际上可能会降低安全性。我们分析了当前的包管理器,表明通过利用漏洞,具有镜像的攻击者每周可以危害或崩溃数百到数千个客户端。我们揭露的问题现在正被许多不同的包管理器维护者纠正。
This work studies the security of ten popular package managers. These package managers use different security mechanisms that provide varying levels of usability and resilience to attack. We find that, despite their existing security mechanisms, all of these package managers have vulnerabilities that can be exploited by a man-in-the-middle or a malicious mirror. While all current package managers suffer from vulnerabilities, their security is also positively or negatively impacted by the distribution's security practices. Weaknesses in package managers are more easily exploited when distributions use third-party mirrors as official mirrors. We were successful in using false credentials to obtain an official mirror on all five of the distributions we attempted. We also found that some security mechanisms that control where a client obtains metadata and packages from may actually decrease security. We analyze current package managers to show that by exploiting vulnerabilities, an attacker with a mirror can compromise or crash hundreds to thousands of clients weekly. The problems we disclose are now being corrected by many different package manager maintainers.