News: 1692217603

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

PowerShell? More like PowerHell: Microsoft won't fix flaws in package gallery ripe for supply chain attacks

(2023/08/16)


A trio of PowerShell Gallery design flaws reported to Microsoft almost a year ago remain unfixed, leaving registry users vulnerable to typosquatting and supply chain attacks, according to Aqua Nautilus.

In [1]a report issued Wednesday, the security shop's software engineer Mor Weinberger and flaw finders Yakir Kadkoda and Ilay Goldman said they tipped off Microsoft in late September.

Yet despite the IT goliath apparently confirming the existence of the flaws - and telling the Aqua team twice that fixes were in place and the issues had been resolved - as of today the bugs are still reproducible, it's claimed. The Aqua trio say they've made a proof-of-concept exploit for two of the three security issues.

[2]

The Windows giant did not immediately respond to The Register 's inquiries, and we will update this story if or when we hear back.

[3]

[4]

Microsoft's PowerShell Gallery is a [5]huge repository of scripts, modules, and desired state configuration (DCS) resources. It boasts it has had nearly 10 billion package downloads to date. This makes it an attractive target for miscreants: if they can abuse the gallery to get malicious code into people's deployments, there could be widespread compromises of information security as well as data theft.

The first problem has to do with PowerShell Gallery's module name policy. It is, we're told, all too easy for someone to create a package in the gallery with a name close to a legit package, have the bogus one stuffed with malware, and wait for developers, power users, and administrators to pull in the bad dependency.

[6]

"We have established that the PowerShell Gallery lacks any form of protection against typosquatting of modules in contrary to other popular package managers such as npm," the three Aqua bods noted.

For instance: most official Microsoft Azure packages use a specific naming pattern "Az[dot]package_name," they explained, such as [7]Az.Accounts . But one popular module maintained by a Microsoftie with more than 10 million downloads, [8]Aztable , doesn't follow this pattern because it doesn't have the dot after "Az."

This makes it relatively easy for miscreants to pull off a typosquatting attack by uploading a new package named Az.Table — note the dot — and trick users into installing a malicious PowerShell module under the attacker's control. To prove the point the team did just that with a proof-of-concept module that phoned home from machines that had the package installed.

[9]

Within hours, they received responses from "several hosts across various cloud services, highlighting the effectiveness of typosquatting and emphasizing the dangers associated with these security flaws," the analysts wrote.

This flaw could be used to pull off a massive supply-chain attack, breach multiple clouds, and compromise many organizations, they opined: "The severity of the impact will be fatal."

Funnily enough, Microsoft must be aware of this issue – which does [10]plague other code warehouses – because one of its engineers created [11]Az.Table to catch typos of AzTable, though the package is unlisted, or hidden from search – more on that later.

[12]US government to investigate China's Microsoft email breach

[13]Microsoft: Codesys PLC bugs could be exploited to 'shut down power plants'

[14]Microsoft, Intel lead this month's security fix emissions

[15]Microsoft hits back at Tenable criticism of its infosec practices

The second issue exists in the landing pages for PowerShell modules – eg, [16]this one – in that it's not immediately obvious who actually wrote and uploaded the resource.

This is because miscreants can upload a malicious package, and write whatever they want in the author, copyright, and description fields on the landing page. Thus anyone could create a bad package, and share in the gallery with Microsoft or AWS supplied as the author. If a user expands the "Package details" section of the page, they'll see a list of user accounts connected to that upload, but these profiles can spoofed, too.

As Aqua put it, "determining the actual author of a PowerShell module in the PowerShell Gallery poses a challenging task." It means it's a bit easier for crooks to masquerade bad packages as code from a legit, trusted developer.

The third flaw allows access to unlisted or hidden packages — such as those containing sensitive data — to anyone willing to do enough digging to find the occasional needle in a haystack.

Although unlisted packages are not supposed to appear in the gallery's search API, the Aqua team found an XML file at [17]/api/v2/Packages that contained "comprehensive information about all packages within the PowerShell Gallery" including unlisted ones.

Microsoft Azure developers targeted by 200-plus data-stealing npm packages [18]READ MORE

There's a URL at the end of the XML file of the format /api/v2/Packages?$skip=[number] . By varying [number] , one can wade through every package, listed or unlisted, and their specific versions. This type of access could be especially useful to criminals looking for highly sensitive data to steal for extortion or espionage purposes, the researchers posit.

"This uncontrolled access provides malicious actors with the ability to search for potentially sensitive information within unlisted packages," the Aqua team said. "Consequently, any unlisted package that contains confidential data becomes highly susceptible to compromise."

They continued: "We were surprised to see publishers who by mistake uploaded their .git/config file containing API keys of GitHub, or a publishing script of the module containing the API key to the gallery itself."

As all three of these shortcomings are still present, according to Aqua, the researchers urge caution when using PowerShell Gallery "until Microsoft fixes the flaws."

We've seen that crooks [19]will use typosquatting and other package repository scouring to infect developers and applications with malware; fingers crossed miscreants don't move from GitHub, NPM, PyPI and others to PowerShell Gallery. ®

Get our [20]Tech Resources



[1] https://blog.aquasec.com/powerhell-active-flaws-in-powershell-gallery-expose-users-to-attacks

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZN1HCdjH2hWds0bXTWcrFgAAAZA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZN1HCdjH2hWds0bXTWcrFgAAAZA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZN1HCdjH2hWds0bXTWcrFgAAAZA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.powershellgallery.com/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZN1HCdjH2hWds0bXTWcrFgAAAZA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.powershellgallery.com/packages/Az.Accounts/

[8] https://www.powershellgallery.com/packages/Aztable

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZN1HCdjH2hWds0bXTWcrFgAAAZA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/07/06/npm_supply_chain_attack/

[11] https://www.powershellgallery.com/packages/Az.table/

[12] https://www.theregister.com/2023/08/14/us_government_investigates_microsoft_breach/

[13] https://www.theregister.com/2023/08/11/microsoft_codesys_bugs/

[14] https://www.theregister.com/2023/08/08/microsoft_intel_august_patch_tuesday/

[15] https://www.theregister.com/2023/08/07/microsoft_power_platform_tenable_criticism/

[16] https://www.powershellgallery.com/packages/PackageManagement/

[17] https://www.powershellgallery.com/api/v2/Packages

[18] https://www.theregister.com/2022/03/24/developers_using_microsoft_azure_targeted/

[19] https://www.theregister.com/2020/04/21/rubygems_bitcoin_malware/

[20] https://whitepapers.theregister.com/



Whiny article, but one true point

Jou (Mxyzptlk)

I am in a lucky position usually not needing anything from there. "ntfsaccess" for example, a package for those who are not willing to learn how to use get-acl / set-acl which can do everything and sometimes even more. Up to now the only thing I needed was a helper to evaluate the "effective access", like the tab of the file explorer. For one time. Unlisted packages being available is the same as unlisted videos on youtube, those who upload should make them private or remove them. Trusting any cloud(-like) storage as open as powershell gallery or github to keep sensitive data inaccessible is naive.

The one true point of the article is the constant inconsistency even within Microsoft own packages to be used for Azure, quite annoying.

fingers crossed

that one in the corner

> miscreants don't move from GitHub, NPM, PyPI and others to PowerShell Gallery.

Well, so long as they do actually move and stop piddling with NPM and PyPi we should be in a better situation.

After all, the people who use Power Shell - certainly those who use it enough to be aware of this gallery thing - are all the highly trained sysops and devops who are aware of these sorts of traps and take especial care over what they are doing.[1]

Whilst PyPi et al are utilised by many more casual users and beginners.

[1] have honestly lost track of whether this is sarcasm or not; given the results of the typosquatting experiment mentioned in the article, safest to assume it is sarcasm.

Connector Conspiracy, n:
[probably came into prominence with the appearance of the KL-10,
none of whose connectors match anything else] The tendency of
manufacturers (or, by extension, programmers or purveyors of anything)
to come up with new products which don't fit together with the old
stuff, thereby making you buy either all new stuff or expensive
interface devices.