{"id":14389,"date":"2014-10-29T16:01:09","date_gmt":"2014-10-29T21:01:09","guid":{"rendered":"http:\/\/bucktownbell.com\/?p=14389"},"modified":"2014-10-29T16:01:09","modified_gmt":"2014-10-29T21:01:09","slug":"the-internet-dodges-another-bullet-with-wget-flaw","status":"publish","type":"post","link":"http:\/\/bucktownbell.com\/?p=14389","title":{"rendered":"The Internet Dodges Another Bullet With Wget Flaw"},"content":{"rendered":"<blockquote><p>&#8220;It was found that wget was susceptible to a symlink attack which could create arbitrary files, directories or symbolic links and set their permissions when retrieving a directory recursively through FTP,&#8221; developer Vasyl Kaigorodov wrote in a Red Hat Bugzilla <a href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1139181\">comment<\/a>. &#8211;<\/p><\/blockquote>\n<p>via <a href=\"http:\/\/www.eweek.com\/blogs\/security-watch\/the-internet-dodges-another-bullet-with-wget-flaw.html\">The Internet Dodges Another Bullet With Wget Flaw<\/a>.<\/p>\n<p>Wget is a linux command that allows a shell script to download a web page and store it to a file.\u00a0 This bug pertains to using a URL to do File Transfer Protocol (FTP) and not HTTP which is what wget was designed for.\u00a0 Here are a couple more snippets of this bug.<\/p>\n<blockquote><p>&#8220;Random bug found by accident, but the implication is that the FTP server can overwrite your entire filesystem,&#8221; Moore <a href=\"https:\/\/twitter.com\/hdmoore\/status\/526752216833466369\">tweeted<\/a> to eWEEK.<\/p><\/blockquote>\n<p>Don&#8217;t use wget for ftp.\u00a0 Don&#8217;t run wget with root permissions.<\/p>\n<blockquote><p>So just to recap here, Wget is on nearly every Linux server in the world, and it had a flaw that could have enabled anyone to overwrite directories on a server. That&#8217;s very serious.<\/p><\/blockquote>\n<p>You should only use wget for http downloads.\u00a0 This doesn&#8217;t sound like one of those Internet Dodges a Bullet problems.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;It was found that wget was susceptible to a symlink attack which could create arbitrary files, directories or symbolic links and set their permissions when retrieving a directory recursively through FTP,&#8221; developer Vasyl Kaigorodov wrote in a Red Hat Bugzilla &hellip; <a href=\"http:\/\/bucktownbell.com\/?p=14389\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1121],"tags":[942,1125,698,1142],"class_list":["post-14389","post","type-post","status-publish","format-standard","hentry","category-current-events","tag-bugs","tag-exploit-vector","tag-security-research","tag-wget"],"_links":{"self":[{"href":"http:\/\/bucktownbell.com\/index.php?rest_route=\/wp\/v2\/posts\/14389","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/bucktownbell.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/bucktownbell.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/bucktownbell.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/bucktownbell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14389"}],"version-history":[{"count":1,"href":"http:\/\/bucktownbell.com\/index.php?rest_route=\/wp\/v2\/posts\/14389\/revisions"}],"predecessor-version":[{"id":14390,"href":"http:\/\/bucktownbell.com\/index.php?rest_route=\/wp\/v2\/posts\/14389\/revisions\/14390"}],"wp:attachment":[{"href":"http:\/\/bucktownbell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/bucktownbell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14389"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/bucktownbell.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}