@cryptotaxi247 / netdata-1 / commits / 0e0499299

Fix notification DoS introduced by PR 3490.

PR #3490 added the `--insecure` option to the cURL calls made by alarm-notify.sh to disable TLS certificate validation and make things work without user intervention if cURL can't find the local TLS certificate store. This allows a trivial DoS of notification deliver via channels other than e-mail and IRC by an attacker hijacking the outbound HTTPS connection, scripting the response, and dropping the notification. It also allows trivial disclosure of information about the state of the system (including disclosing what software is running on the system and potentially certain aspects of it's configuration). Here, we change the unconditional use of `--inescure` to be dependent on the value of a variable in health_alarm_notify.conf, and make that variable default to not enabling the option while putting a big warning right next to it about the security implications. Most users should never need to disable TLS certificate validation.

Austin S. Hemmelgarn committed Mar 1, 2018 at 08:27 UTC 0e0499299702edd1873cdbb948f7a3eb9c13910a
2 files changed +25 -2
conf.d/health_alarm_notify.conf
+16
@@ -61,6 +61,22 @@ curl=""
61 # If not found, irc notifications will be silently disabled.
62 nc=""
63
64 +#------------------------------------------------------------------------------
65 +# extra options for external commands
66 +#
67 +# In some cases, you may need to change what options get passed to an
68 +# external command. Such cases are covered here.
69 +
70 +# Control TLS certificate validation for cURL.
71 +# If set to yes, disable certificatie validation.
72 +# Otherwise, cURL will validate TLS certificates normally.
73 +# ******************************WARNING****************************************
74 +# Disabling this validation by setting the below variable to 'yes'
75 +# makes it trivial for someone to block notification delivery through most
76 +# mechanisms other than email and IRC, and may additionally leak sensitive
77 +# information about the system state.
78 +curl_insecure="no"
79 +
80 #------------------------------------------------------------------------------
81 # NOTE ABOUT RECIPIENTS
82 #
plugins.d/alarm-notify.sh
+9 -2
@@ -112,6 +112,13 @@ docurl() {
112 return 1
113 fi
114
115 + if [ "${curl_insecure}" = "yes" ]
116 + then
117 + insecure='--insecure'
118 + else
119 + insecure=''
120 + fi
121 +
122 if [ "${debug}" = "1" ]
123 then
124 echo >&2 "--- BEGIN curl command ---"
@@ -120,7 +127,7 @@ docurl() {
127 echo >&2 "--- END curl command ---"
128
129 local out=$(mktemp /tmp/netdata-health-alarm-notify-XXXXXXXX)
123 - local code=$(${curl} --insecure --write-out %{http_code} --output "${out}" --silent --show-error "${@}")
130 + local code=$(${curl} ${insecure} --write-out %{http_code} --output "${out}" --silent --show-error "${@}")
131 local ret=$?
132 echo >&2 "--- BEGIN received response ---"
133 cat >&2 "${out}"
@@ -132,7 +139,7 @@ docurl() {
139 return ${ret}
140 fi
141
135 - ${curl} --insecure --write-out %{http_code} --output /dev/null --silent --show-error "${@}"
142 + ${curl} ${insecure} --write-out %{http_code} --output /dev/null --silent --show-error "${@}"
143 return $?
144 }
145