3 ms·
looks like Discord is vulnerable to this too, oopsie
by phit_ 5y ago
looks like Discord is vulnerable to this too, oopsie
- jhgg 5y agoWe don't transcode video, so no.
- phit_ 5y agothe player is malfunctioning anyway, similarly to those videos that report short runtime and then go on forever that get passed around quite frequently
- jhgg 5y agoThis is how the video element works in chromium. I suspect it looks at the same metadata field. Beyond leading to a bit of absurd UI state though it's not the same kind of issue that this post describes, which deals with trying to transcode these kinds of videos which could multiply storage utilization on the backend.
- deathanatos 5y agoI presume you're Discord eng. You must do some sort of pass or parse of it, because every now and then I'll upload something and it will fail to process and result in what I'll call "the sad Discord poop"…
- jhgg 5y agoWe try to grab the first frame to show a preview. But if we can't for whatever reason, that's when the sad poop appears :(
- LinuxBender 5y agoNot discord, but the default player is vulnerable to many different crash shenanigans. I get them sent to me all the time to look into and its usually just people using bogus timestamps, bogus seek times or concatenating multiple videos of different resolutions/rates that the player can't handle. If there was a way to get discord to spawn VLC for playing videos by default this would be less of a problem.
- ronsor 5y ago> get discord to spawn VLC So rather than loading the bogus videos in a sandboxed Chromium instance, you want to load them in an unsandboxed VLC instance? I smell eventual RCE.
- LinuxBender 5y agoYes. - VLC has decades of battle hardening and entirely discards all the aforementioned nonsense. In a perfect world, both Discord and VLC would be sandboxed themselves, but I accept that this world is far from perfect. Discord could at least sanitize anything that strays from a filename when passed to VLC. - Discord is already vulnerable to crashes from multimedia. This has been a long running problem that has not been resolved by sandboxing in Electron. The folks at Discord will not be able to resolve this with code changes in Electron AFAIK. If you can crash it, there is potential for an RCE. What that RCE can effectively accomplish will entirely depend on sandboxing boundaries external to the application, not sandboxing within the application. In reference to sandboxing, I could make a document that explains how to enable the OS wide sandboxing features of Windows 10 [1] VirtualSecureMode / DeviceGuard / CredentialGuard and Linux SELinux / AppArmor. I don't have one for MacOS. I should add, don't enable the Windows 10 security features if you depend on any virtualization outside of Hyper-V. Enabling those will break all hypervisors that don't rhyme with Hyper-V. I should add that my solution for Discord is to not preview videos or play them in the client. I click on the links and VLC plays them but that is not the default behavior of the application. [1] - https://techcommunity.microsoft.com/t5/iis-support-blog/windows-10-device-guard-and-credential-guard-demystified/ba-p/376419#:~:text=%20Windows%2010%20Device%20Guard%20and%20Credential%20Guard,separate%20from%20Device%20Guard%2C%20the%20Credential...%20More%20 https://techcommunity.microsoft.com/t5/iis-support-blog/wind...
- foepys 5y agoAren't quite a few Android security fixes every month related to the media framework? Are those not severe in a browser context because it's sandboxed?