Huawei DME forcefully deleting your systems certificate store, ar tool and more
This one is another perfect example for "Enterprise software".
At a customer I noticed an ongoing discussion why some systems, where the Huawei DME was installed, were having trouble with all sorts of internal services. As soon as anything required a SSL/TLS connection it wouldn't work.
- Internal RPM-Repositories requiring HTTPS? Not working
- Agents for various tasks (patching, monitoring, etc.) couldn't establish outgoing connections
- Cron-Tasks utilizing system internal tools who in turn require an SSL/TLS connection to be established (like downloading something with curl via HTTPS) stopped working and started throwing errors
- Additionally files from another software packed with
arsuddenly couldn't be extracted anymore
In short: Something was really, really wrong here.
System administrators at the client noticed that, indeed, all sorts of files under /etc/pki/ had been deleted. This, at least, explained the various SSL/TLS issues. Also zypper, the package manager being used, listed the tool ar as installed, but the binary /usr/bin/ar was deleted and missing alike.
All this couldn't have a single root-cause, right? Someone must have messed things up really badly by using many wrong commands, right? Like a new admin executing commands on the wrong machine, right?
Turns out, there is this wonderful Huawei script called os_harden.sh albeit it achieves quite the contrary.
I won't list the script here in full here for copyright reasons, but the first few lines make wish to slam my head into the nearest wall as hard as I can. As someone at Huawei really thought it is a good idea to delete the local system certs truststore? Bypassing any installed package manager!? Why!?
And why do you delete some bash-completion files? These are ever only used when you manually use these tools with tab-completion. Nothing in your tooling should worry about these files let alone throw any sort of error because of them. Do they really thing to make it any harder for an malicious actor by deleting the bash completion files for some tools? People at Huawei: If a malicious actor is already on the system you have a plethora of other problems than the attacker being able to use tab-completion on tools like nmap. In fact, chances are high that the attacker just executes scripts anyway and isn't affected by this. And if you must remove files, do so properly via the systems package manager! Words can't describe how angry I am about the level of shown dilettantism.
Oh.. And they forcefully deleted /usr/bin/ar, again by bypassing the systems package manager. Why they remove ar? Only they know. Maybe some of their people saw some "evil script" utilizing ar and thought it clever to remove ar? Why this person then also didn't delete tar, zip, gzip and all the others (Anyone using unrar? 😅) is unclear to me, these are used far more commonly in "evil scripts"..
This is system hardening done by a person who knows nothing about real security and how real-world attacks happen. Congratulations, you messed up your customers machine!
Naming the function remove_useless_cert is just the icing on the cake.. As the deleted files are anything but useless. Even if your "Enterprise software" doesn't need them, all other OS processes surely do!
user@host:~# cat /temp/DeployTool/hcb/software/clm/plugins/DJ/scripts/upgrade/shellFiles/os_harden.sh
#!/bin/bash
# Copyright (c) Huawei Technologies Co., Ltd. 2021-2021. All rights reserved.
set -e
set +e
SSH_CONFIG_FILE="/etc/ssh/sshd_config"
MAX_STARTUPS="MaxStartups 2000:30:2000"
function remove_useless_cert() {
# 删除不符合要求的证书
rm -rf /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
rm -rf /etc/pki/ca-trust/extracted/pem/objsign-ca-bundle.pem
rm -rf /etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt
rm -rf /etc/rhsm/ca/redhat-uep.pem
rm -rf /etc/pki/tls/certs/ca-bundle.crt
rm -rf /etc/pki/tls/certs/ca-bundle.trust.crt
rm -rf /etc/pki/tls/cert.pem
# 删除调试工具相关文件
rm -rf /usr/share/bash-completion/completions/gcc
rm -rf /usr/share/bash-completion/completions/gdb
rm -rf /usr/share/bash-completion/completions/iftop
rm -rf /usr/share/bash-completion/completions/nc
rm -rf /usr/share/bash-completion/completions/nmap
rm -rf /usr/share/bash-completion/completions/strace
rm -rf /usr/share/bash-completion/completions/tcpdump
rm -f /usr/bin/ar &> /dev/null
# 升级环境修改检查产品目录脚本日志文件权限
[ -e /var/log/dme/check_required_path.log ] && chmod 640 /var/log/dme/check_required_path.log
[...]
This is exactly the reason why system administrators use the term "Enterprise software" as a swearword.




