6 ms·
tl;dr: if you run untrusted code from malicious actors, bad things will happen. Nothing new here.
by XCabbage 8y ago
tl;dr: if you run untrusted code from malicious actors, bad things will happen.
Nothing new here.
- sbierwagen 8y agoAs a moderately sophisticated user, I wouldn't have expected the function RemoveExtraSpaces to immediately enable a RCE attack. It sounds pretty innocuous.
- okket 8y agoThe 'RunScript' keyword does give a slight, glaring hint IMHO.
- vectorEQ 8y agomost people who play wow don't know what a script is. they just click mobs and do raids. it's not obvious atall to a lot of people, just like phone scams, people who go door to door to scam, or even spam emails. Its for a good reason these things still go on: they are still effecive against people who aren't developers or IT enthousiasts, which most gamers aren't. they like games, not scripting engines and LUA interpreters or w/e
- bialpio 8y agoYou would if someone told you to replace trim() with eval(). :-)
- thecatspaw 8y agoits not the function thats the problem, its replacing it with the run function, which (to me) are obviozs signs of shenanigans
- krageon 8y agoJust the fact that RunScript is being substituted for something else should set off alarm bells.
- SmellyGeekBoy 8y agoNot everyone who plays WoW is a developer.
- mywittyname 8y agoThe OP specified "moderately sophisticated."
- nfriedly 8y agoI don't think RemoveExtraSpaces has any RCE, but it is overwriteable. The "hack" is tricking the user into overwriting it with a different function called RunScript.
- nightski 8y agoWhich is complicated by the fact that any addon (which many users use a dozen or more) can do this without the user knowing at all on initialization.
- jdmichal 8y agoAny add-on added by the user is already executing in the client's space and has zero need for a vulnerability like this. It's like saying that any program running on my computer could exploit a remote code execution bug... I mean, yes, it could. But why would it, when it already has local execution rights?
- Qwertystop 8y agoBecause if the add-on just opens up a backdoor, the author can do more specifically targeted things at their whim rather than blasting everyone who installed it? Harder to get caught.
- horsawlarway 8y agoStill zero need for this kind of exploit. The author of the addon can already do specifically targeted things at whim at a later point in time.
- nightski 8y agoI mean it was already maliciously exploited in a highly used addon. It was a lot easier to slip in a short one liner than some highly suspicious "hack the user" blob of code. It was also extremely flexible. They could then do different things to each person instead of one fixed attack.
- jschwartzi 8y agoThe issue is that Lua treats functions as "first-class," meaning that they are stored in variables like other data. This is how named functions are created within the language, and function syntax is sugar for initializing a variable and stuffing a function into it. This works with API functions also, which is why this works.
- andrewstellman 8y agoThe vast majority of players won't realize that they can run untrusted code just by typing a few characters into a chat window. To be fair, most chat windows don't work that way.
- danShumway 8y agoThis attack would be pretty easy to mitigate. Why does WoW allow you to run scripts in your chat window? Who needs that functionality? Yes, don't run untrusted code as a user, but also developers should be practicing defense in depth[0]. This isn't like pasting something into a web browser's dev console or a Bash prompt, WoW has the ability to just outright turn this behavior off. Look at something like the Signal source code, they flat out turn off webviews entirely[1]. So an entire class of phishing attacks just vanishes, regardless of what they're doing to block XSS or malicious links. WoW should do the same thing - your chat window should not have access to its host environment, if it even needs the ability to run scripts in the first place. [0]: https://en.wikipedia.org/wiki/Defense_in_depth_%28computing%29 https://en.wikipedia.org/wiki/Defense_in_depth_%28computing%... [1]: https://github.com/signalapp/Signal-Desktop/blob/development/main.js#L726 https://github.com/signalapp/Signal-Desktop/blob/development...
- typomatic 8y ago> Why does WoW allow you to run scripts in your chat window? Who needs that functionality? The "chat" window in WoW is more like a shell interface/CLI than a pure chat window and it's been that way since the inception of WoW. The mod system is loosely dropped on top of it: basically add-ons in WoW amount to bash scripts. It's a pretty hacky system that seems like it was made to add modding capability as quickly as possible during development. The fact that such an integral system has never been rewritten isn't hard to believe.
- danShumway 8y agoI can buy that -- but wouldn't they still at some point want to make the main chat window for the game into some kind of safer wrapper around the bash prompt? This is coming from someone who doesn't play WoW; is it common for a mod to expose custom commands in chat or something? Or are mods maybe using it as a buffer to send commands? I guess if they're detecting and popping up a warning prompt, but they're not willing to get rid of the prompt and just always escape the input, there must be some stuff out there that utterly depends on players clicking "allow". That's baffling to me, but I am often baffled.