5 ms·
Announcing cross_fuzz, a potential 0-day in circulation, and more
- ximeng 16y agoMicrosoft not only not acknowledging security problems, but asking them not to be disclosed after several months of inaction. Search engine hits to this guy's site indicate that these problems are being independently discovered by people based in China. http://lcamtuf.coredump.cx/cross_fuzz/known_vuln.txt http://lcamtuf.coredump.cx/cross_fuzz/known_vuln.txt Bugs in all other browsers, although with better responses it seems. Interesting problems to solve here, both technically and socially. --- This guy's blog is great, read more of it! Some recent articles: http://lcamtuf.coredump.cx/electronics/ http://lcamtuf.coredump.cx/electronics/ - geek's guide to electronics for programmers who don't know this stuff http://lcamtuf.coredump.cx/word/ http://lcamtuf.coredump.cx/word/ - cool physical project - threat level indicator --- Author Wikipedia page: http://en.wikipedia.org/wiki/Micha%C5%82_Zalewski http://en.wikipedia.org/wiki/Micha%C5%82_Zalewski
- viraptor 16y agoI heard about the MS inaction from many sources now. For example IKVM.net developer wrote a couple of times: "P.S. By my new policy, I won't be filing a bug with Microsoft since they have amply demonstrated not to care about external bug reports."
- robin_reala 16y agoI’d also highly recommend his 'Silence on the Wire' book ( http://lcamtuf.coredump.cx/silence.shtml http://lcamtuf.coredump.cx/silence.shtml ), it’s a really readable full-stack overview of potential security problems. In fact, I’m going to dig my copy out and read it again.
- m0nastic 16y agoHe's also the author of Skipfish (a fairly new web scanner), which I've been making a lot of use of the past few months. It's still fairly beta, but already I find it to be more useful than WebInspect in many cases.
- tptacek 16y agoThat's a pretty horrible indictment of WebInspect, because Skipfish virtually never finds anything for us (we ban scanners on our teams, but I like Zalewski and tend to run Skipfish just for kicks).
- m0nastic 16y agoI suppose it's somewhat of a backhanded compliment. I honestly wouldn't pay money for the results I get from WebInspect (we have licenses for it, so we use it). I swear that WebInspect has gotten noticeably worse the past year and a half or so. Prior to that, it would at least occasionally find something interesting; but I honestly can't remember the last time it found something that wasn't a false positive. As to SkipFish, I would say that the past three applications I've run it against it's found at least one interesting thing (which is high praise for automated tools in our industry).
- viraptor 16y agoAny specific reasons you don't use them? It's a pretty interesting view from a security guy really... most of those I heard before say something like "it doesn't hurt to leave it running, while we do our stuff manually - sometimes it works". Also, did you mean fuzzers in general or only web scanners?
- tptacek 16y agoJust scanners. Everyone uses Burp's fuzzer. And in the rare cases we end up doing network pentests, we will use Nessus. Scanners make testers stupider. Even if you are conscientious about using them responsibly†, they still work to turn off the part of your brain that thinks about the kinds of flaws they do a good job of detecting. If you say you'll only run them at the end of a engagement to see if there's anything you missed, now you're working with a safety net. † And we've worked on plenty of projects that had previous runs from teams that weren't responsible about scanners, with predictably horrific results.
- 16y ago
- sabat 16y agoAlthough MS' reaction does appear to be irresponsible, a browser crash is hardly the worst security issue I can imagine. If that's all this guy is finding -- it's all he mentions in his post -- then this sounds more like security for security's sake than anything practical.
- ximeng 16y agoI don't know the details, but a fully attacker controlled EIP sounds likely to be exploitable doesn't it? Possibly data leakage from the browser, maybe arbitrary execution if the attacker is lucky. This sounds likely at the least to put an attacker in a better place to socially engineer a user into installing malware.
- daeken 16y agoIf you can control EIP, you can run arbitrary code, period. It might be difficult depending on whether ASLR is in use or not, but it can always be done.
- ximeng 16y agoDoesn't this assume you can get the code you want to execute into memory? And that the page it ends up in is marked as executable?
- daeken 16y agoShort answer: No Long answer: It depends on what you define as arbitrary code execution. In a good number of cases, you can use ROP to execute whatever "code" (made up of little bits of existing program code repurposed for your needs) you wish, and accomplish whatever you want to accomplish. In many cases, this is finding your "real" code and setting memory protection such that you can jump into it. In effect, if you have control over EIP, you've already owned the system; it might not be easy to do everything you want to do, but it's effectively always possible.
- 16y ago
- rphlx 16y agoSadly you don't need a fuzzer to crash adobe flash (at least on x86_64 linux). A few hours browsing top-25 websites normally does the trick. There is a big reason Chrome sandboxes plugins, and its named "Adobe".