5 ms·
I fail to see how this can actaully be used as an exploit. As some commenters have said, yes, it may be a risk to some open source tools where there is poor due
by fullstackchris 5y ago
I fail to see how this can actaully be used as an exploit. As some commenters have said, yes, it may be a risk to some open source tools where there is poor due diligence for merge request review process - but that is almost never the case.
Otherwise, if you own your own code, this obviously isn't an issue. (Unless, of couse, for some reason you want to program exploits into software at your organization :) )
Heck, even GitHub already shows a warning for files that have bi-directional unicode...
A bit of an overemotional title if you ask me.
- pietroalbini 5y agoIt's this research that prompted GitHub to show warnings, they didn't appear as of yesterday.
- willvarfar 5y agohttps://blog.rust-lang.org/2021/11/01/cve-2021-42574.html https://blog.rust-lang.org/2021/11/01/cve-2021-42574.html has a nice clear example. Full Stack Chris reviews some code that he thinks says: if access_level != "user" { // Check if admin This may be an open source project. This may be an internal bad egg (a very common threat; insider jobs are actually one of the absolute top risks to a company). Or this code may be injected by an attacker who has gained access to the repo and is leaving backdoors that they hope to survive long after their access is blocked or leaving backdoors to make deployed production systems vulnerable. Etc. And Chris won't notice that the computer will execute: if access_level != "user{U+202E} {U+2066}// Check if admin{U+2069} {U+2066}" { This is not just an attack on compiled languages. Scripting languages are just as vulnerable.
- kiklion 5y agoSorry, still don’t get it. Isn’t the issue that they are using magic strings? If the strings were something like RoleConstants.Admin then this is avoided? Though I don’t understand the point of the Unicode characters in the comment string so I must be missing something.
- tzs 5y ago> Though I don’t understand the point of the Unicode characters in the comment string so I must be missing something. There is no comment string.
- kiklion 5y agoSo after reading other parts, I get where I was mistaken but still believe proper coding practices of avoiding magic strings would avoid many of the potential issues. My mistake was thinking the initial Unicode character was changing the comparison string similar to a non printable character could. But instead it flips the ordering so that the comment is part of the comparison string and then the string is terminated.
- db48x 5y agoDon’t get hung up on strings, you can execute this attack with just comments. Look at the other examples in the paper. The idea here is that you make part of the comment appear to be outside of it, and thus appear to be code that will be executed. You can reshuffle the text arbitrarily, so you can move text backwards to appear to be before the start of the comment, or forwards to appear to be after the end of the comment. If you really want to, you can treat the whole line as an anagram, and rearrange the individual letters into any order you like. This could enable really clever attacks where any use of an enum constant appears to be a use of a different one.
- sethammons 5y agoAnd the dev wrote test cases (negative ones too!). The test fails and shows admin privileges for the normal user. Debugging ensues. I'd hope.
- wizzwizz4 5y agoThe test has the same kind of change. It passes, and nobody thinks to look at the obviously-correct code.