A password on the public website SEC-91

OpenSecurity · Easy · Incident · about 25 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Priya Raman opened SEC-91 at 09:20SEV-2

An external scanner reports that the depot's public website serves a file with a database password in it. The access log says someone already downloaded it.

Anything in the web root is public. A backup of the Waybill environment file sat there for a week, including the Ledger database password, and the access log shows someone downloaded it.

"Deleting the file stops the next download. It does nothing about the one that already happened." (Priya)

bin/ledger-admin can rotate the password. Waybill reads its password from waybill.env on every request, so it will pick up the new one immediately.

Your task

Remove every copy of the credentials from the website, make waybill.env readable by its owner only, rotate the leaked password, and confirm Waybill is healthy with the new one.

On the machine

  • var/log/www/access.log
  • srv/www/
  • opt/waybill/waybill.env
  • bin/ledger-admin, ops/urls.txt

Timeline

Last weekBefore an upgrade, someone copies waybill.env into srv/www as a "quick backup".
Oct 2 03:12An outside scanner requests the backup copy. 200.
09:15External scanner reports the file.
09:20SEC-91.

Done when

  1. The public website serves no copy of the credentials.
  2. opt/waybill/waybill.env is readable by its owner only.
  3. The leaked password is revoked, and Waybill is healthy with the new one.

Hints

Hint 1

grep the access log for the backup's file name. Who fetched it?

Hint 2

Anything under srv/www is public. Remove the backup from there.

Hint 3

chmod 600 opt/waybill/waybill.env

Hint 4

bin/ledger-admin rotate waybill prints a new password. Put it in waybill.env and curl the health URL.

Show the solution

Find the copy the access log shows being downloaded (`grep ' 200 ' var/log/www/access.log`, then `grep -rl LEDGER_PASSWORD srv/www`) and remove it, chmod 600 opt/waybill/waybill.env, run bin/ledger-admin rotate waybill, write the new password into waybill.env, and confirm the health URL answers 200.