Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-07-04 Thread Wouter Verhelst
On Mon, Jun 22, 2015 at 10:03:52PM +0200, Geert Stappers wrote: +Template: preseed/accept_preseed_from_DHCP +Default: false +_Description: Accept a preseed URL from the DHCP server? :-( We have allready 'auto-install/enable' ( 'auto' for short ) Which does not serve the same

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-22 Thread Christian PERRIER
Quoting Aliz 'Randomdude' (randomd...@gmail.com): +Template: preseed/accept_preseed_from_DHCP +Type: boolean +Default: false +_Description: Accept a preseed URL from the DHCP server? + The DHCP server has provided extra commands or customisations to s/has provided/provided Better English,

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-22 Thread Geert Stappers
+Template: preseed/accept_preseed_from_DHCP +Default: false +_Description: Accept a preseed URL from the DHCP server? :-( We have allready 'auto-install/enable' ( 'auto' for short ) See also https://www.debian.org/releases/jessie/mips/apbs02.html.en#preseed-auto Geert Stappers

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-22 Thread Aliz 'Randomdude'
On 18 June 2015 at 14:11, Christian PERRIER bubu...@debian.org wrote: (no need to CC me or debian-boot to answers as bug report answers already go to debian-boot) Ah, sorry. Thanks for letting me know. Quoting Aliz 'Randomdude' (randomd...@gmail.com): +Template:

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-18 Thread Christian PERRIER
(no need to CC me or debian-boot to answers as bug report answers already go to debian-boot) Quoting Aliz 'Randomdude' (randomd...@gmail.com): +Template: preseed/accept_preseed_from_DHCP +Type: boolean +Default: false +Description: Should we accept a preseed URL from a DHCP server? + Your

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-18 Thread Aliz 'Randomdude'
On 16 June 2015 at 10:37, Wouter Verhelst wou...@debian.org wrote: But if you boot off CD-ROM or USB or some such? Then the situation is much different. While I agree that having preseeding in that case can be useful, I can also understand the POV that the system *defaulting* to using such a

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-16 Thread Wouter Verhelst
On Sun, Jun 14, 2015 at 04:48:20PM +0200, Geert Stappers wrote: control: tag -1 mordac I don't think handwaving and tagging wontfix is the right play here. Now tagging with 'mordac'. For those new to Mordac, get a first impression at http://dilbert.com/strip/2007-11-16 And

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-14 Thread Geert Stappers
control: tag -1 mordac I don't think handwaving and tagging wontfix is the right play here. Now tagging with 'mordac'. For those new to Mordac, get a first impression at http://dilbert.com/strip/2007-11-16 And http://dilbert.com/search_results?terms=Mordac for a complete overview of Mordac,

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-13 Thread Aliz Hammond
Package: debian-installer Severity: important Tags: d-i, security Dear Maintainer, I emailed the following to debian-security and was advised to open a public bug for it. Debian-installer will accept a preseed URL provided via a DHCP option, even when installed from CD-ROM. No authentication

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-13 Thread Geert Stappers
On Sat, Jun 13, 2015 at 04:32:04PM +0100, Aliz Hammond wrote: Due to this, an attacker on the local network can spoof a DHCP responce pointing to their own preseed file, which can do all sorts of mischief (such as adding users or executing commands). So the actual problem is that the local

Bug#788634: debian-installer: Accepting a preseed URL from DHCP allows attacker to hijack installation

2015-06-13 Thread Cyril Brulebois
Geert Stappers stapp...@stappers.nl (2015-06-13): On Sat, Jun 13, 2015 at 04:32:04PM +0100, Aliz Hammond wrote: Due to this, an attacker on the local network can spoof a DHCP responce pointing to their own preseed file, which can do all sorts of mischief (such as adding users or executing