Re: [xmpp] IQ Handling vulnerabilities

"Joe Hildebrand (jhildebr)" <> Thu, 06 February 2014 21:58 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id 42CA11A044D for <>; Thu, 6 Feb 2014 13:58:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -10.036
X-Spam-Status: No, score=-10.036 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.535, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 8kNkGwUzsF5p for <>; Thu, 6 Feb 2014 13:58:48 -0800 (PST)
Received: from ( []) by (Postfix) with ESMTP id 7DC361A044C for <>; Thu, 6 Feb 2014 13:58:48 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple;;; l=1797; q=dns/txt; s=iport; t=1391723927; x=1392933527; h=from:to:subject:date:message-id:references:in-reply-to: content-id:content-transfer-encoding:mime-version; bh=pH1JY0HDIIJmL4rK/1Qa79MMZtyRWLhSonUoGuDSnvM=; b=O4k9U//+rxN7eOC2dRmw9N7snb5XKitp1QmzITXPu5VVpqgZyAlJRp/k 4/R8ViDcckNAhuJupQ7g4MpcikrWLet7tHf9nHYsHzSskiJomKlcoC0YT f4rcmKYREgoAz5G6q/7MP9ngziZsKbC9ft4fgJosNOUjvc0gS0LkZOL9x Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgwFADYE9FKtJV2Z/2dsb2JhbABZgww4V753gQ8WdIImAQEEAQEBNzQbAgEINhAnCyUCBAESG4dqDc0HEwSPAYQ4BJgrkiGDLYIq
X-IronPort-AV: E=Sophos;i="4.95,796,1384300800"; d="scan'208";a="18583106"
Received: from ([]) by with ESMTP; 06 Feb 2014 21:58:47 +0000
Received: from ( []) by (8.14.5/8.14.5) with ESMTP id s16Lwlvp017967 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Thu, 6 Feb 2014 21:58:47 GMT
Received: from ([]) by ([]) with mapi id 14.03.0123.003; Thu, 6 Feb 2014 15:58:46 -0600
From: "Joe Hildebrand (jhildebr)" <>
To: "" <>, XMPP Working Group <>
Thread-Topic: [xmpp] IQ Handling vulnerabilities
Thread-Index: AQHPIy5NY8RkLrfuaUqqtuYhYOIBR5qopVEA
Date: Thu, 6 Feb 2014 21:58:45 +0000
Message-ID: <>
References: <>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
user-agent: Microsoft-MacOutlook/
x-originating-ip: []
Content-Type: text/plain; charset="us-ascii"
Content-ID: <>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [xmpp] IQ Handling vulnerabilities
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: XMPP Working Group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Thu, 06 Feb 2014 21:58:50 -0000

(as individual)

I think this is a very important issue.  I'm worried about the security
impact, and I think we need to give good guidance.

(as co-chair)

Who else thinks we need to work on this?

Can we start with an individual I-D that lays out the problem and
solution?  That would allow us to make good decisions about what the next
step would be.  Kev, that might be pretty quick for you to write...

On 2/6/14 3:26 AM, "Kevin Smith" <> wrote:

>Hi folks,
>  Discussion in the XSF and at the recent XMPP Summit has shown that
>there are widespread issues with handling of iq responses in XMPP
>software. This is probably something we need to consider handling.
>The basis of this is that many libraries/clients
>a) Only check the id of an iq error/result, not the sender, to check
>it matches one they've sent (Very Wrong)
>b) Use predictably generated ids for stanzas (ill-advised, but not
>strictly wrong)
>c) Use known resource strings (bad, but not strictly wrong)
>In conjunction, this leads to various obvious attacks with differing
>levels of severity, but for the sake of enumerating some, with some
>good fortune with timing against a vulnerable client you can: Fake
>contacts', or even their own, vcards; fake their roster so they think
>people have 'unfriended' them, or that they have already added someone
>unknown; deny capabilities discovery; make them think their server
>doesn't have a MUC service; and the list goes on and on.
>We certainly need to call this out explicitly in 3920ter, We might
>want to publish something in the interim.
>xmpp mailing list

Joe Hildebrand