Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Arivia
Mar 17, 2011

Rust Martialis posted:

Did the image fail to convey itself?

Does the Silent Hill wiki run on Java or something?

Adbot
ADBOT LOVES YOU

Esran
Apr 28, 2008

evil_bunnY posted:

2.16 is apparently still problematic LMBO

2.16.0 should have deleted the lookup-placeholders-in-log-strings code, and also have disabled JNDI by default. Is it still vulnerable in some way? Google doesn't turn up anything for me about 2.16 still being vulnerable, just the 2.15 released last week.

some kinda jackal
Feb 25, 2003

 
 

evil_bunnY posted:

2.16 is apparently still problematic LMBO

source??

I am going to literally be lynched by developers if true.

KillHour
Oct 28, 2007


Martytoof posted:

source??

I am going to literally be lynched by developers if true.

Sounds like you're having a rough time. Want to work with me as a consultant instead?

some kinda jackal
Feb 25, 2003

 
 
I'm seriously wondering if mid 40s is a good time to learn a trade.

KillHour
Oct 28, 2007


Come to the dark side and get me a referral bonus argue about whether XML or JSON is better. It's JSON. JSON is better.

Jowj
Dec 25, 2010

My favourite player and idol. His battles with his wrists mirror my own battles with the constant disgust I feel towards my zerg bugs.

Esran posted:

2.16.0 should have deleted the lookup-placeholders-in-log-strings code, and also have disabled JNDI by default. Is it still vulnerable in some way? Google doesn't turn up anything for me about 2.16 still being vulnerable, just the 2.15 released last week.

I saw people on Twitter posting about it but the only thing I could find was some PR about how all the docs are bad and don't tell people that untrusted input is dangerous. which like, fine, they probably are bad! but that's not really what I care about in this context.

did anyone find other reasons for 2.16 to be considered bad?

BaseballPCHiker
Jan 16, 2006

evil_bunnY posted:

2.16 is apparently still problematic LMBO

Where did you read this? I need to schedule some extra PTO if true.

some kinda jackal
Feb 25, 2003

 
 
2.16 is bad for the following reason:

- it's still log4j

evil_bunnY
Apr 2, 2003

Esran posted:

2.16.0 should have deleted the lookup-placeholders-in-log-strings code, and also have disabled JNDI by default. Is it still vulnerable in some way? Google doesn't turn up anything for me about 2.16 still being vulnerable, just the 2.15 released last week.
You're correct, it's my bad. They found more vulns in .15 but they were patched in .16

Mustache Ride
Sep 11, 2001



You almost gave me a loving heart attack. I just got everything patched and was planning on starting my 2 week vacation at noon today.

Jerk

evil_bunnY
Apr 2, 2003

Sorry!!

some kinda jackal
Feb 25, 2003

 
 
lmao

we're all running on caffeine and no sleep so no harm no foul but yeah I also had a heart attack -- like literally my face sank

Internet Explorer
Jun 1, 2005





At this point even if there was another round, that shits staying for a while. Between the exhaustion from this past round and the upcoming holidays, I don't think anyone has any time or energy left.

some kinda jackal
Feb 25, 2003

 
 
Yeah exactly. That's why I pivoted from software currency to REMOVE THE loving CLASS where we have that option

Not sure how that works for vendor garbage and where it affects support SLAs where you start removing code lol

ngl I kind of want to proactively pull the class from 2.16 too lol

evil_bunnY
Apr 2, 2003

Internet Explorer posted:

At this point even if there was another round, that shits staying for a while. Between the exhaustion from this past round and the upcoming holidays, I don't think anyone has any time or energy left.
I run the infra some of the people with log4j issues are using at our org and it's been really funny watching the process-nazis try to either put their head in the sand or go around process they had insisted they needed.

Jowj
Dec 25, 2010

My favourite player and idol. His battles with his wrists mirror my own battles with the constant disgust I feel towards my zerg bugs.
alright. 2.15 DOS has been upgraded to RCE.
https://logging.apache.org/log4j/2.x/security.html

2.16 now has a DOS found in it.

Tryzzub
Jan 1, 2007

Mudslide Experiment
hahahahha

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Jowj posted:

alright. 2.15 DOS has been upgraded to RCE.
https://logging.apache.org/log4j/2.x/security.html

2.16 now has a DOS found in it.

Is it? I think that's the original CVE. Or am I not reading that page correctly?

Esran
Apr 28, 2008
I don't see any vulnerability listed for 2.16 on that page?

BaseballPCHiker
Jan 16, 2006

Esran posted:

I don't see any vulnerability listed for 2.16 on that page?

Same. Quit trying to give me heart attacks.

some kinda jackal
Feb 25, 2003

 
 
Can we please cite a source if we're saying lol look at this thing that just happened, even if it's some dumb tweet :(

e: not anyone specific but just in general lol

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
https://issues.apache.org/jira/browse/LOG4J2-3230
Certain strings can cause infinite recursion
Affects Version/s: 2.8, 2.8.1, 2.8.2, 2.9.0, 2.9.1, 2.10.0, 2.11.0, 2.11.1, 2.11.2, 2.12.0, 2.12.1, 2.13.0, 2.13.1, 2.13.2, 2.14.0, 2.13.3, 2.14.1, 2.15.0, 2.16.0
Fix Version/s: 2.17.0

Description
If a string substitution is attempted for any reason on the following string, it will trigger an infinite recursion, and the application will crash: [censored to avoid cloudflare blocking me from SA again].


hopefully this bug report is bad/it's easily fixed because lol

Sirotan
Oct 17, 2006

Sirotan is a seal.


:negative:

evil_bunnY
Apr 2, 2003

Malloc Voidstar posted:

hopefully this bug report is bad/it's easily fixed because lol
VINDICATED!

Proud Christian Mom
Dec 20, 2006
READING COMPREHENSION IS HARD
Just turn it all off and come back to it Jan 3rd

Internet Explorer
Jun 1, 2005





Proud Christian Mom posted:

Just turn it all off and come back to it Jan 3rd

Esran
Apr 28, 2008
Going by the comments on that issue, it sounds like it only causes a crash (on 2.16) if the bad string is part of the appender config, not if the bad string is simply logged, i.e. the attacker has to get that string into the logging config somehow. Hopefully that's the case, if so that's not too serious.

Edit: But also why is their string substitution applied recursively, that seems like a weird feature to have.

some kinda jackal
Feb 25, 2003

 
 

Esran posted:

that seems like a weird feature to have.

log4j 2: that seems like a weird feature to have

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


This is the vuln that never ends, it just goes round and round my friends

Absurd Alhazred
Mar 27, 2010

by Athanatos

Cup Runneth Over posted:

This is the vuln that never ends, it just goes round and round my friends

Someone logged it without knowing what {itwas}

more falafel please
Feb 26, 2005

forums poster

Esran posted:

Edit: But also why is their string substitution applied recursively, that seems like a weird feature to have.

The PS3's standard library printf() did this, for some reason. We couldn't ship games with printf() enabled (they checked symbols), so it didn't matter for shipping, but I ran into an issue printing UE3 level hashes that could have % in them, which means they could have %n in them, which means they could write to some arbitrary address

BlankSystemDaemon
Mar 13, 2009




KillHour posted:

Come to the dark side and get me a referral bonus argue about whether XML or JSON is better. It's JSON. JSON is better.
Why settle for the inferior choice when there's UCL?

KillHour
Oct 28, 2007


Proud Christian Mom posted:

Just turn it all off and come back to it Jan 3rd

It is inevitable that there will eventually be found an exploit so bad that it's cheaper to just not do any business for a couple weeks.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://issues.apache.org/jira/browse/LOG4J2-3230

BlankSystemDaemon
Mar 13, 2009




Far be it for me to poopoo on the proud tradition of Kramering into threads, and while I know you mean well, I'd invite you to look about 10 posts prior, on this very page.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
Apologies, for I am tired

BlankSystemDaemon
Mar 13, 2009




Rooney McNibnug posted:

Apologies, for I am tired
Totally understandable, and very :same:

I didn't mean to imply that you should absolutely under no circumstances do something like that, I'm not the dad of you or anything.

KillHour
Oct 28, 2007


BlankSystemDaemon posted:

I'm not the dad of you or anything.

Maybe not but I'm my own grandpa.

Adbot
ADBOT LOVES YOU

Jowj
Dec 25, 2010

My favourite player and idol. His battles with his wrists mirror my own battles with the constant disgust I feel towards my zerg bugs.

Rooney McNibnug posted:

Apologies, for I am tired

i told my lady the other day that I haven't been this tired since I was a teen staying up 3 days I play quake, I am beaaaaat

I hope your poo poo is almost done and you get to nap soon ✨

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply