Vulnerability bug in ICE's proxy renewal (Advisory-SVG-2012-4039) - PARTLY-PASSED
Link to Advisory: SVG:Advisory-SVG-2012-4039
Tested that jdl with nasty commands is not exectued.
2012-10-08 12:09:44,718 ERROR - iceCommandSubmit::execute() - TID=[25977088] Error during submission of jdl= Transient Exception is:Failed to create a delegation
id for job https://cert-27.cnaf.infn.it:9000/NkVc8BIJMAXbjDGby9waeQ: reason is Authorization failure: Cannot map grid user onto a local account
2012-10-08 12:09:44,799 ERROR - iceThreadPoolWorker::body() - Command execution got FATAL exception: Error submitting job to CE [https://tutor04-cream.cnaf.infn.i
t:8443/ce-cream/services/CREAM2]: Failed to create a delegation id for job https://cert-27.cnaf.infn.it:9000/NkVc8BIJMAXbjDGby9waeQ: reason is Authorization failu
re: Cannot map grid user onto a local account
2012-10-08 12:09:54,706 ERROR - iceCommandDelegationRenewal::renewAllDelegations() - Proxy renewal failed: [ERROR - /usr/bin/glite-wms-ice-proxy-renew: glite_rene
wal_core_renew() failed: Error connecting Myproxy server emitb-myproxy.civ.zcu.cz; echo MC was here > /tmp/intrusion; for proxy /var/ice/persist_dir/84EC42AD362E6
2283BE3B74622EA779A659F7F2C.betterproxy: Unknown host "emitb-myproxy.civ.zcu.cz; echo MC was here > /tmp/intrusion;"Unable to connect to emitb-myproxy.civ.zcu.cz;
echo MC was here > /tmp/intrusion; - timeout=[120] - myproxyserver=[emitb-myproxy.civ.zcu.cz; echo MC was here > /tmp/intrusion;] - proxy=[/var/ice/persist_dir/8
4EC42AD362E62283BE3B74622EA779A659F7F2C.betterproxy] - HOSTCERT=/var/glite/wms.proxy - HOSTKEY=/var/glite/wms.proxy]
|