l3nz

l3nz

You may have seen that a critical security vulnerability has been disclosed in the OTP SSH implementation that could permit an attacker to execute arbitrary code sans any authentication under certain conditions.

If your run an Erlang SSH server, you need to act immediately.

More information in Unauthenticated Remote Code Execution in Erlang/OTP SSH · Advisory · erlang/otp · GitHub

Showing Posts 1 to 10

realcorvus

realcorvus

I’ve published a writeup on this - What the Critical Erlang SSH Vulnerability Means for Elixir Developers

The summary is if you’re using Phoenix, you are most likely not affected. If you are using Nerves with SSH in production, you may be vulnerable. The Nerves team is aware of this issue and they are actively working on a solution so people can easily update.

D4no0

D4no0

I see only 3 OTP versions mentioned, does this mean that OTP-24 and older don’t suffer from this issue?

realcorvus

realcorvus

I believe they are vulnerable, the root cause of the bug is related to the SSH handshake in Erlang. OTP-24 and older seem to be out of support, so they don’t get security updates - Erlang | endoflife.date

LostKobrakai

LostKobrakai

Erlang/OTP supports the last 3 OTP releases with security updates and patches.

https://github.com/erlang/otp/blob/master/SECURITY.md

dch

dch

Perhaps a Mod can move this to Elixir News category, this is an extremely serious vulnerability, albeit only for those who:

  • use the erlang/otp ssh app as a daemon
  • and have exposed this functionality to the internet

There is already proof-of-concept code.

Work-around

  • use firewall rules to block external connectivity to your ssh port
  • don’t start the erlang ssh daemon within your elixir app startup

Fix

  • re-build with a patched OTP release & re-deploy

Affected versions

  • <= OTP-27.3.2
  • <= OTP-26.2.5.10
  • <= OTP-25.3.2.19
  • any older Erlang/OTP releases <=OTP-24

Patched versions

NB only supported OTP releases are 25+

  • => OTP-27.3.3
  • => OTP-26.2.5.11
  • => OTP-25.3.2.20
axelson

axelson

Scenic Core Team

There’s a fix out for this now. If you have an outdated system then I’d heartily recommend upgrading!

ricksonoliveira

ricksonoliveira

I read it and I have a live app on fly.io using Phoenix, but when I nmpa’ed my app it says port 22/tcp is open for ssh.
I guess I’m vulnerable even though I use Phoenix and Fly.io, right?

realcorvus

realcorvus

Most likely no, port 22 is used internally by Fly.io for fly ssh console, so it’s highly unlikely you are running an Erlang SSH server on that port.

For you to be vulnerable, you have to do all of these:

  1. Enable :ssh as an extra application in your mix.exs file. (It is off by default)
  2. Configure your Elixir app to accept Erlang SSH connections on a non-standard port
  3. Manually expose that running service via the Fly.io feature external port ranges, launched in 2023 - Annoucement: External port ranges - announcement - Fly.io (my original post is technically wrong when it says this it not possible on Fly.io, however I hope this whole explanation shows why it is so unlikely)

When you nmap a Fly.io hosted app it will show port 22 is open, but that’s for Fly.io official use, your application is not running the Erlang SSH server on that port. For example, run:

nc your_domain_here 22

If it returns SSH-2.0-Erlang/VERSION then you are vulnerable. Most likely it will return nothing (I just tested it), and you are not vulnerable.

ricksonoliveira

ricksonoliveira

So I guess I’m really not because nc your_domain_here 22 returned nothing.

Thanks! :smiley:

Where Next? Top

Trending in Discussions Top

AstonJ
As the title says, please share what you’ve been up to with Elixir. Whether that’s been learning it, looking into it, making stuff with i...
2977 94592 917
New
cblavier
Hey there, It’s been more than a year since we started using LiveView as our main UI library and building a whole library of UI componen...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
heathen
Quite interesting article Google brought me. Didn’t find any mentions about it here. What do you think in general? Would you use togethe...
New
AstonJ
Since we have deprecated our Erlang sections (as we have dedicated Erlang Forums now) let’s add this thread for those who’d like to post ...
New
maennchen
:warning: Security advisory: Decimal DoS vulnerability A vulnerability has been published for decimal where very large exponents can cau...
New
Null-logic-0
What IDE or editor are you using for Elixir development? Personally, I use Zed, and I really like it, but sometimes I wish there were a ...
New

Other Trending Topics Top

marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
webofbits
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself. My main conc...
#ai
New
webofbits
Aludel - LLM Evaluation Workbench Aludel is an embeddable Phoenix LiveView dashboard for evaluating and comparing LLM prompts across mult...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews