11 ms·
Backdooring JavaScript using minifier bugs
- samuellb 11y agoThis makes me think that there could be similar bugs in the browser, when it JIT-compiles or optimizes Javascript code. That could be used to take control of the whole browser/OS if used in an add-on/extension (given that it has sufficient privileges).
- makomk 11y agoThere have been similar bugs in browser JITs that allow websites to escape the sandbox - usually incorrect optimisations that cause the JIT to elide bounds checks when it can't safely do so, probably since those are the easiest to exploit.
- bcrypt 11y agoThere's actually a fair number of security researchers looking at browser-level exploits like those in JIT (c.f. pwn2own). My colleague Chris Rolhf co-authored a cool study on attacking JIT: https://www.nccgroup.trust/us/about-us/resources/jit/ https://www.nccgroup.trust/us/about-us/resources/jit/
- yoz-y 11y agoI wonder. Should one ever use minified javascript code on a server? Assuming that you are using it on your own server and not distributing the code to clients. Is there any benefit to it?
- nathankleyn 11y agoAlmost certainly not, if only because it's another layer of indirection when debugging and for this use you're not limited by distribution size. There is a potential benefit if the minifier can apply some performance optimisations, but one would hope V8 et al are already doing most of these and more. Even for client-side applications, HTTP2 + Web Assembly will eradicate concatenating and minifying JS files soon.
- bcrypt 11y agoOP here. Agree there probably isn't much benefit to minifying server-side code. However, I wouldn't be surprised if things like Closure Compiler were useful server-side. Not convinced that HTTP2 will eradicate minifiers; it makes bundling files less useful, but minifying still gets rid of bytes. Then again, I'm not a web performance expert. :)
- nathankleyn 11y agoSorry, that's a mistake - I meant to write "HTTP2 + Web Assembly" (which will take the place of file concatenation and minification).
- gliptic 11y agoWhy would HTTP2 eradicate the minifier? It seems completely orthogonal to minification.
- nathankleyn 11y agoEdited, that's a mistake - I meant to write "HTTP2 + Web Assembly" (which will take the place of file concatenation and minification).
- gliptic 11y agoWebAssembly will only be applicable to asm.js-style code, not JavaScript in general.
- phpnode 11y ago> Is there any benefit to it? Well, in theory yes. When determining whether a specific function can be inlined into its call site, V8 looks at the length of the function source code to try and guess whether it's worth it. Functions longer than 600 characters (including comments) cannot be inlined and therefore they will typically be slower. Whether that makes any meaningful difference to your application performance really depends on the application. In most cases it won't.
- nitrogen 11y agoInteresting. Is there a reason why the parsed AST size isn't used instead of raw source code size?
- phpnode 11y agoV8 doesn't use an AST, it uses a CFG, but I believe it comes down to efficiency - it's far cheaper to look at the length of a string than to traverse a graph, and by its nature JS needs very fast compilation times. This is probably one of those heuristics that works well enough on enough real world code, even though everyone knows it's suboptimal. I've heard that the turbofan compiler will remove this limitation but that's still very much work in progress.
- chrisdevereux 11y agoEven if you don't use a minifier on the server, a library built using any kind of transpiler (babel, coffeescript, typescript...) could be susceptible to this kind of attack.
- ef4 11y agoThis may sound entirely wacky, but I have seen it make a major performance impact on nodejs. The reason is that V8 uses heuristics to decide which functions get inlined, and the raw source code length is one of the heuristics. Making the source for a function shorter may cause V8 to inline it more aggressively.
- jand 11y agoNice to read text on a clever find. Could somebody please confirm or invalidate my understanding, that this backdoor is just exploitable in addition with other (severe) issues? An attacker would have to have the ability to tailor/manipulate JS scripts which should be under control of the victim? Or am i mistaken?
- bcrypt 11y agoThat's correct. I did not discover vulnerabilities in existing libraries or add backdoors to any of them. :) The attack scenario described in the post is (1) attacker writes some plausible-looking patches to an existing library like jQuery, (2) attacker convinces library maintainer to merge the patches, (3) someone builds the library with a buggy minifier, which creates the actual backdoor.
- tracker1 11y agoIt's interesting all the same, It's kind of why exploits in very popular things like wordpress become problematic for so many for so long.
- NullCharacter 11y agoReally slick. To translate the idea behind compiler backdoors to JS minifier backdoors is pretty clever.
- hspak 11y agoApplying DeMorgan's Law to reduce a few characters in JS seems really overkill... Reading this makes it seem hardly worth saving a few bytes over.