5 ms·
I predict a rash of eventual FireEye, Cisco, and other vendor zero days in the near to mid future. If you are a nation state actor what better way to find zero
by Trisell 6y ago
I predict a rash of eventual FireEye, Cisco, and other vendor zero days in the near to mid future. If you are a nation state actor what better way to find zero days then to get the source code and find the bugs to exploit. This is the only thing that makes sense that would be worth the risk of attacking companies such as FireEye and Microsoft.
- kevin_morrill 6y agoWhy would this actually be true? If it’s easier to find in source, Microsoft probably would have found it. Ever single feature there goes through multiple security reviews and there is tons of code linting. All the penetration testers I have met don’t even bother looking at source. They just start trying things they think will flummox the software.
- hguant 6y ago>They just start trying things they think will flummox the software. This works...until you go against a target that's heard of fuzzing before and has the time and money to do it to their own code. The really interesting Windows exploits require a combination of "throwing stuff that will flummox the software" and a deep level understanding of structures hidden to the average developer. Look at Yardin Shafir's really wonderful blog post about developing a kernel bug to a PoC - there's a lot of moving parts and security checks in modern windows, and having the source is a HUGE help.
- muricula 6y agoYardin Shafir's excellent blog post started with a bug found purely through fuzzing by an MS employee security researcher.
- kevinarpe 6y agoI tried Googling to find this blog post. Did you mean to write Yarden Shafir? If yes, maybe it was this blog post? https://windows-internals.com/printdemon-cve-2020-1048/ https://windows-internals.com/printdemon-cve-2020-1048/ I also found another hint about their findings in this PDF written by Yarden's co-researcher Alex Ionescu: https://www.usenix.org/system/files/woot20_slides_ionescu.pdf https://www.usenix.org/system/files/woot20_slides_ionescu.pd.... One of the slides specifically mentions the use of fuzzing tools to find these issues. If there are other, better links I don't know about, please kindly share. :)
- muricula 6y agoForgot to check for replies. In particular, I was thinking of this blog post: https://windows-internals.com/exploiting-a-simple-vulnerability-in-35-easy-steps-or-less/ https://windows-internals.com/exploiting-a-simple-vulnerabil... Thanks for the correction, sorry I typoed her name. Here's a tweet from the original finder: https://twitter.com/gabe_k/status/1330966182543777792?s=20 https://twitter.com/gabe_k/status/1330966182543777792?s=20 Yarden & Ionescu's work are both really top notch. Also anything by Google Project Zero if you want to do a deep dive on the subject.
- Razengan 6y ago> If it’s easier to find in source, Microsoft probably would have found it. Umm sir, have you somehow missed seeing the quality of Microsoft products in the last few decades.
- tptacek 6y agoThis is pretty silly. Source code for Cisco and Microsoft products has been circulating since the dawn of the Internet. Meanwhile, Microsoft has some of the most meticulously reverse engineered code on the planet. People who want to illicitly mint zero days out of Microsoft products already have the tools to do so.
- hda2 6y agoI don't think it's silly. Having access to high-level source code beats combing through disassembler output.
- intern4tional 6y agoDisclaimer: am Microsoft employee. tplacek's point isn't that source is worse than disassembler output, it's that governments already have and have had access to source for a while (by design as Microsoft does provide source access to many customers, partners, etc). The tooling to dissemble built versions and craft exploits has also existed for a long while. If source access enabled a rash of zero days, that point in time would have come long in the past.
- dmix 6y agoHow long has Microsoft been giving source code to China officially? I know they made that a public stipulation. Not that alternative means were likely employed for a number of years before that.
- blihp 6y agoSince 2003: https://www.cnet.com/news/china-to-view-windows-code/ https://www.cnet.com/news/china-to-view-windows-code/
- dmix 6y agoThis is basically ending this whole thread then. Nation state hackers with Microsoft source code 'on my'. Even commercial-wise I doubt it's much concern for making products. Source code doesn't equal a software business, every business knows that. Unless there's some unreleased AI source code sort of thing.
- myrandomcomment 6y agoCompanies like Microsoft and Cisco have made their source code available to governments for years, for whatever that is worth. The US government has full access to all the MS source code.
- richardowright 6y agoDoes this include access to thinks like the Azure Control Plane components? In my mind, that code has a different exposure.