5 ms·
Or MS has fuzzed it but hasn't devoted as many computational resources as Google has. They say that fuzzing-produced bugs have come out regularly over the years
by aab0 10y ago
Or MS has fuzzed it but hasn't devoted as many computational resources as Google has. They say that fuzzing-produced bugs have come out regularly over the years, so clearly no one else had before applied as many resources as Google did...
- MaulingMonkey 10y agoOr used a different fuzzer with different mutators, or did blackbox non-coverage non-tracing fuzzing, or fuzzed the entire program instead of individual methods, or simply missed a program/driver/???, or ... EDIT: RTFAing, Google even mentions using longer runtimes: > As shown in the table, the crashes were reported in three iterations: the first one obviously contained the bulk of the issues, as the fuzzer was hitting a lot of different states and code paths right from the start. The second and third iterations were run for a longer time, in order to shake out any crashes which might have been masked by other, more frequently hitting bugchecks. EDIT x2: Also, it looks like they moved it out of the Kernel in Windows 10, so that's good. > It's also worth noting that while the elevation of privileges scenario is mitigated in Windows 10 by the architectural shift to performing font rasterization in a user-mode process with restricted privileges, an RCE in the context of that process is still a viable option (although much more limited than directly compromising the ring-0 security context).
- pierrec 10y agoAlso RTFAing, the authors express their surprise at how easy some of the vulns/crashes were to find using very basic fuzzing. So while @x0x0 might be jumping to conclusions a bit harshly, saying that MS did little to no fuzzing on their font libraries is actually a reasonable guess.
- aab0 10y agoThat, however, contradicts their other assertion that past researchers have fuzzed the fonts and found many vulnerabilities. They can't both be easily true, so there must be something further going on.
- pierrec 10y agoMeh. "it was trivial to discover with a dumb fuzzer, and it's surprising that such a bug could even survive until 2015, with so much work being supposedly put into the security of font processing." (Emphasis mine.) I suppose they might be underplaying the complexity of the steps required to reproduce their finds, but it really doesn't look like it. Honestly I'm not that surprised. At times like this I'm reminded of the sheer amount of security holes out there in the wild and I just want to chuck my computer in the lake.
- BraveNewCurency 10y agoTurns out lakes are security thru obscurity. They do not provide as much security as previously thought. Consider an active volcano next time.
- MaulingMonkey 10y agoDBAN all the disks, smash all the chips, degauss the scrap and ship straight to your nearest neutron star. Proceed to direct said neutron star into the nearest black hole. Accelerate said black hole to at least five 9s of c, along whichever vector is least convenient. The backup tapes? I'm sure the trash is fine.
- wyldfire 10y agoOr MS has fuzzed it, it was terribly productive, and they fixed the bugs without confessing how they found them.