Hey look, Secunia reads FreshMeat!

    I hope no one is paying
    Secunia for their security advisories. I release gtalkbot 1.0 (where you had to pass the GTalk user name and password on the command line), and then changed that behaviour in 1.1. The Secunia rocket scientists figured out all by themselves that this was bad. Bad enough for a security advisory?

    A security issue has been reported in gtalkbot, which can be exploited by malicious, local users to disclose sensitive information.

    The problem is that certain user credentials are passed to the application as arguments on the command line. This can be exploited to gain knowledge of usernames and passwords of other services via the process list.

    The security issue is reported in versions prior to 1.1.


    Ummm, the GTalk account is created for the purpose, and so it's not uber secure anyways. In fact, it's only visible to local users, who are presumably trusted anyways given that gtalkbot also needs the unauthenticated telnet interface to MythTV enabled to work. Wow. I assume that Secunia just reads every FreshMeat security release, and makes an announcement about it. Oh, and those three nearly paragraphs took over two weeks!

    Update: but wait, there's more! I made it into the US Federal Government's vulnerability database too, complete with an incorrect "Authentication: Not required to exploit". I guess the Feds can't read python code?

    Update: perhaps Secunia is just reprinting this lame advisory? Do these people just reprint each other's work all the time? Again with the hoping people aren't earning money by making suckers think they're helping...

    The fun continues: yay for SecWatch and systembodyguard!

    Tags for this post: gtalkbot(S)

posted at: 16:08 | path: /gtalkbot | permanent link to this entry
There are 2 comments on this post, and 1 comments which didn't survive moderation. 1 were blocked by trained gerbils. Click here to see them.