& cplSiteName &

OpenDaylight Patches 'Serious Vulnerability' – After Four Months

Mitch Wagner
12/17/2014
50%
50%

There's bad news and worse news about OpenDaylight security.

The bad news: The open source OpenDaylight SDN controller has a security flaw that could allow an attacker to take over an SDN network.

The worse news: The security consultant who discovered the flaw reported it in August, but couldn't get anybody to listen to him.

But here's some better news: Patches are in the works, and the OpenDaylight community is working on a process for managing security bugs.

The "Netdump" security flaw was discovered by Gregory Pickett, part of the managed security services group for Hellfire Security. The vulnerability allows remote attackers to gain access to any file related to network configuration applications. Vulnerable files include hashed network credentials, which could be hacked to give attackers full control of the network, Pickett says.

After discovering the flaw, Pickett went to the OpenDaylight website looking for directions on how to report security issues or contact developers, but came up dry. He finally found a web form to contact OpenDaylight, and filled that out. "No one actually replied to me. I just got added to the mailing list," Pickett says.

He adds, "At first I was irritated, then I found it amusing. I'm still getting regular messages from them."


Want to know more about SDN? Visit Light Reading's SDN technology content channel.


With no response from OpenDaylight, Pickett presented a description of the flaw at the DEF CON security conference, which was August 7-10, and posted a description to the Bugtraq mailing list Aug. 11.

As part of the DEF CON talk, Pickett also looked into the Floodlight controller, an open source SDN controller affiliated with Big Switch Networks . Pickett found problems there too. "In the case of Floodlight, there didn't seem to be any controls in place at all," he said. The northbound API has no authentication, or encryption, which will allow anyone to take over full control of the network. Pickett says Big Switch promptly contacted him about the security vulnerability and told him that its implementation of Floodlight includes fixes for the security holes. (See Who Does What: SDN Controllers and Big Switch Intros Flagship Big Cloud Fabric – At Last.)

After the presentation, on August 16, Pickett was contacted by Grant Murphy of Red Hat Inc. (NYSE: RHT), who said he was trying to put a procedure in place for managing security in OpenDaylight, according to emails from Murphy that Pickett shared with Light Reading.

Open source strength
Despite the problems, OpenDaylight Project executive director Nicolas "Neela" Jacques says the incident demonstrates the strength of the open source process.

    This is the first time our security response system was tested and it brought to light one glaring issue, which is that the security alias wasn't broadly advertised on the main ODL site. (This has since been fixed: http://www.opendaylight.org/project/contact)

He adds:

Pickett found an issue and tried to share it through a web form which was inactive. It came on our radar [Monday] through our main community mailing list and as soon as it did, we fixed it.

This is a testament to why open source software works. Greg could see the code, saw there was an issue and flagged it through the web form which unfortunately was a dead link. There are a dozen other ways the info could have been shared directly with the community because--as you saw--once it got to them, it was immediately resolved.

Pickett says he tried querying on the community mailing list in August and received no response.

Jacques says:

Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
From The Founder
Either we perform a complete 'factory reset' on the way the telecom industry creates and deploys virtualization, or we face the consequences.
Flash Poll
Live Streaming Video
Charting the CSP's Future
Six different communications service providers join to debate their visions of the future CSP, following a landmark presentation from AT&T on its massive virtualization efforts and a look back on where the telecom industry has been and where it's going from two industry veterans.
LRTV Custom TV
The Urgency of Commercial 5G Services

4|26|17   |     |   (0) comments


The progress of 5G has been closely monitored in the industry. At the 2017 Brooklyn 5G Summit, the sense of urgency for a commercial 5G launch had started to surface among operators.
Women in Comms Introduction Videos
How Diversity Helps Comcast Mirror Its Customer Base

4|26|17   |   2:55   |   (0) comments


Diversity brings innovation, creative ideas and a way to reflect the broad spectrum of your customer base, Comcast Director of Customer Experience Jenelle Champlin says.
LRTV Huawei Video Resource Center
Mobile Operators & Video

4|25|17   |     |   (0) comments


Ovum's Ed Barton discusses the latest mobile operator strategies for mobile video.
LRTV Custom TV
Infinera Introduces Instant Network

4|20|17   |     |   (1) comment


Mike Capuano, vice president of marketing at Infinera, discusses the advancement from Instant Bandwidth to new Instant Network capabilities, which include Bandwidth License Pools, Moveable Licenses and Automated Capacity Engineering (ACE).
Women in Comms Introduction Videos
Vodafone's Eubank on Sponsors, Mentors & Moving On Up

4|19|17   |   4:25   |   (0) comments


Vodafone America's Head of Operations Kimberly Eubank breaks down the difference between a sponsor and a mentor and shares why both made a big difference in her career.
LRTV Custom TV
NYC Auto Show: Are We Smart Yet?

4|18|17   |     |   (0) comments


The auto industry is facing some big transformations as electric vehicles, autonomous technology and connected cars are seen as the future of the industry. During the much-anticipated NY international auto show, there was an emergence of new technology and mobility service on the show floor. Aside from performance, brands like Lincoln, Hyundai, Honda, Mercedes and ...
LRTV Huawei Video Resource Center
The Impact of Video

4|18|17   |     |   (0) comments


David Mercer from Strategy Analytics discusses the impact of video on current strategies.
LRTV Custom TV
Pardeep Kohli Discusses Network Transformation & the Market Opportunity for the 'New' Mavenir Systems

4|13|17   |     |   (0) comments


In a brief discussion at MWC 2017, Heavy Reading analyst Adi Kishore talks to Pardeep Kohli, CEO, Mavenir Systems about the creation of the 'new Mavenir' and some of the key challenges facing operators in today's market. A key theme of the discussion centers around operator need for software-only, virtualized solutions and how they will need to adapt to ...
Women in Comms Introduction Videos
Tech Maverick Shares Her Tips for Gender Inclusivity

4|12|17   |   7:28   |   (0) comments


Wendy Hall Bohling, a corporate escapee, author and gender exclusivity consultant, tells her story of sexism, bias and progress along the road to gender equality in the workforce.
LRTV Huawei Video Resource Center
Huawei at MWC 2017

4|11|17   |     |   (0) comments


At Mobile World Congress 2017, the biggest mobile industry gathering of the year, Huawei showcased its new innovations and solutions with the theme "Open Road," which focuses on cloud, 5G, operation transformation, videos and consumer-oriented products. Its campaign has been recognized by three awards given by GSMA.
LRTV Custom TV
China Telecom NFV Infrastructure on RSD

4|6|17   |     |   (0) comments


Lynn Comp, senior director of market development of Intel, is joined by Chong Zhang, storage engineer at Inspur and Ou Li Yan, architect for technology strategies of China Telecom, for a discussion of what NFV brings.
LRTV Custom TV
Nokia's IMPACT Software Demo

4|6|17   |     |   (0) comments


Khamis Abulgubein of IoT market development at Nokia demonstrates IMPACT (intelligent management platform for all connected things), a software solution with a horizontal approach to managing any device on any application.
Upcoming Live Events
May 15-17, 2017, Austin Convention Center, Austin, TX
May 15, 2017, Brazos Hall - Austin, TX
May 15, 2017, Austin Convention Center - Austin, TX
June 6, 2017, The Joule Hotel, Dallas, TX
All Upcoming Live Events
Infographics
With the mobile ecosystem becoming increasingly vulnerable to security threats, AdaptiveMobile has laid out some of the key considerations for the wireless community.
Hot Topics
Surprise! AT&T Markets 4G Advances as '5G Evolution'
Dan Jones, Mobile Editor, 4/25/2017
Did Verizon Outbid AT&T for Straight Path?
Dan Jones, Mobile Editor, 4/25/2017
Netflix Set to Enter China
Mari Silbey, Senior Editor, Cable/Video, 4/25/2017
First Year TIPs the Scale Toward Success
Denise Culver, 4/24/2017
Like Us on Facebook
Twitter Feed
BETWEEN THE CEOs - Executive Interviews
One of the nice bits of my job (other than the teeny tiny salary, obviously) is that I get to pick and choose who I interview for this slot on the Light Reading home ...
TEOCO Founder and CEO Atul Jain talks to Light Reading Founder and CEO Steve Saunders about the challenges around cost control and service monetization in the mobile and IoT sectors.
Live Digital Audio

Playing it safe can only get you so far. Sometimes the biggest bets have the biggest payouts, and that is true in your career as well. For this radio show, Caroline Chan, general manager of the 5G Infrastructure Division of the Network Platform Group at Intel, will share her own personal story of how she successfully took big bets to build a successful career, as well as offer advice on how you can do the same. We’ll cover everything from how to overcome fear and manage risk, how to be prepared for where technology is going in the future and how to structure your career in a way to ensure you keep progressing. Chan, a seasoned telecom veteran and effective risk taker herself, will also leave plenty of time to answer all your questions live on the air.