8 ms·
This is mind boggling. NSO used a compression format's instructions to create logic gates and then from there "a small computer architecture with features such
by usmannk 5y ago
This is mind boggling. NSO used a compression format's instructions to create logic gates and then from there "a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations", all within a single pass of decompression. Combine this with a buffer overflow and you've got your sploit.
- airstrike 5y agoThat reads like some handwavy explanation of a hack in a movie scene... "Now I just have to embed a 64-bit computer architecture into my compression algorithm and... boom. We're in."
- athenot 5y agoThen you can "Enhance". https://www.youtube.com/watch?v=Vxq9yj2pVWk https://www.youtube.com/watch?v=Vxq9yj2pVWk Joking aside, this does illustrate the "magical" properties of technology to the layperson. As a corollary, failure modes end up quite suprising and hard to reason about without a certain amount of proficiency in these technologies.
- vmception 5y agoEnhancing works with trained AI these days Maybe not for evidence collection, but for pleasing a human being to go follow a lead sure
- Jerrrry 5y ago>Maybe not for evidence collection, Kyle Rittenhouse was possibly almost convicted due to "enhance with AI".
- vmception 5y agoBring it up with the appeals court in the event it occurs, unless you run out of money. Dont run out of money.
- deleted 5y ago[deleted]
- danaris 5y agoI've seen some examples of this. It's very clearly trained on a white-male dataset. I've also seen it "enhance" an image of a resistor into a human face. I don't care how much AI you have, you can't add back data that wasn't in the original image. The best you can hope to do is get a vague approximation, and you must have a very, very good (comprehensive) training dataset for that to be remotely viable.
- pizza 5y agoThe premise of the technology is not adding more information to the image. But rather realizing that the image may have a description that is a lot smaller than its file size suggests; then it becomes a matter of rendering it using world-aware encodings. The resolution may appear higher but it is actually a filtration of the original data. And there’s nothing to say that simply because the current technology is overfitted to their present-day datasets, that such a filter (that is actually useful for common images, or enhancement by leveraging known/ few-shot other examples consisting of the same target object) cannot exist.
- Zigurd 5y ago> It's very clearly trained on a white-male dataset. TBF the Beatles look amazing in the Peter Jackson documentary, though the original material was shot on 16mm.
- shakna 5y agoThere is a world of difference upscaling something digital, and something analog. 16mm film actually does contain more information than could be shown with the original film. We have better scanning techniques today that can extract that information. Upscaling something digital, does require creating information out of thin air, on the other hand.
- fulafel 5y agoWell, that and the explanation is missing the details. Conceptually being able to construct something like that from XOR and NOT primitives is stuff from undergrad computer engineering curriculum. But it's certainly a respectable feat to find this combination of compression format and the vulnerability therein of all the supported formats, and think to apply it like this.
- dylan604 5y ago"I found a 3rd party library that uses eval, so we just send it code we want to run and...boom. We're in." "I found a popular chat app that after install leaves a tool with full sudo privileages behind for us to take advantage of located clickityclickity... here. We're in." Sometimes, it can be even more pedestrian sounding. Hackers don't always have to be clever if other people are absolutely dumbasses before their arrival.
- joe_guy 5y agoTo be clear, what this exploits is nothing like what you've mentioned. The article does a very good job of describing the relevant parts of the image format. They built a VM inside of an images single pass decompression route. I'd highly recommend reading the article. This is just one of the exploits in a very large chain. To quote some of the nations top security researchers: > Based on our research and findings, we assess this to be one of the most technically sophisticated exploits we've ever seen, further demonstrating that the capabilities NSO provides rival those previously thought to be accessible to only a handful of nation states. This has nothing in relationship to eval().
- dylan604 5y agoI'm thinking you're missing the larger idea. The whole point is that while these "geniuses" did something really "impressive" and difficult, there are just as really not-impressive and not-difficult things found in the wild that have caused problems as well.
- user-the-name 5y agoWhy bring that up? It is something everybody knows and it adds nothing to this conversation.
- dylan604 5y agoIt's called counterpoint. It was actually found interesting by several people, but you can have your opinion that you don't find it intersting. It actually did add to the conversation as there were multiply replies to it. Your comment about it is the thing that doesnt really add to anything.
- d0mine 5y agoIt reminds me about Nand to Tetris course https://www.nand2tetris.org https://www.nand2tetris.org
- robotnikman 5y agoIts amazing how they took a buffer overflow and ran with it to create a whole turing complete machine. Its mind boggling how complex these exploits can be, no wonder they sell for millions
- toxik 5y agoIt also demonstrates how much more work there is after “buffer overflow” until you get to RCE.
- onphonenow 5y agoNow - that is a big change. Historically the jump from overflow to RCE was much much shorter. Still the iMessage attack surface is just massive and running in an unsafe language kind of crazy?
- MayeulC 5y ago> Historically the jump from overflow to RCE was much much shorter. Not really. I am about to read the article, but it sounds like return-oriented programming[1] chaining "gadgets" that are small bits of existing code that you can re-purpose into executing arbitrary code by manipulating the stack. Extremely common exploitation technique, even if not trivial. Who said an exploit or RCE was trivial to exploit? Edit: I was a bit quick to dismiss. The technique is certainly interesting, although the article doesn't go into the details of how the control flow is handled and where that register is stored. However, I'd like to point out that ROP is quite complex on its own, as it's kind of like using a computer with an arbitrary instruction set that you have to combine to create higher-level functions, hence my original confusion. [1] https://en.wikipedia.org/wiki/Return-oriented_programming https://en.wikipedia.org/wiki/Return-oriented_programming
- itp 5y agoSuffice it to say, this exploit was not simply chaining gadgets.
- inasio 5y agoIt seems we're now at the point where anything Turing complete can be a vector. Wow...
- sterlind 5y agothis wasn't Turing-complete until they exploited it to make it so. JBIG2 executes arbitrary binary bitmap operations, but sequentially (no looping.) using the exploit they presumably found a way to send it into a loop, probably by overwriting the pointer to the next segment or something. theoretically I guess you don't need that, but you'd have to send a payload linear in size to the number of cycles expected to run the shellcode, and that wouldn't lend itself to a processor-like design - it'd just be too big.
- markus_zhang 5y agoThis reminds me of the original story of Mel in which Mel managed to do similar things with assembly. Amazing stuffs and wish I had a chance to work with similar genius.
- formerly_proven 5y agoBasically anything that exceeds the regular category is risky and difficult to secure. See weird machines / langsec. This is a prime example.
- staticassertion 5y agoWell, when combined with an integer overflow at least.
- sterlind 5y agoabsolutely brilliant, genius work. I was confused about how they got the thing to run for an unbounded amount of time, but I guess they probably have the final operation at the end of a "processor cycle" be to overwrite the next SegRef so that it loops back to the current SegRef. I'd love to see the thing in more detail - what the shellcode looks like, how the CPU was designed, everything. a scummy company but such transcendental brilliance..
- ChuckMcM 5y agoI read through this and my jaw dropped. Pretty amazing detective work and a really amazing exploit. Presumably you could run Doom on it :-). Sometimes I feel like it's hopeless but my brain cannot help but work on creating solutions to this sort of problem.
- mderazon 5y agoIndeed amazing and also very well written article. I wonder how much time it took to develop, I assume the whole general programming language from NAND gates is not something they had to come up with from scratch. Putting the pieces together though, that's a work of art
- albrewer 5y agoThey probably defined some microcode operations -> created a minimal assembly language -> wrote it in C -> hand-optimized the asm output -> compiled to "machine" code All the steps are things you cover in a computer engineering degree (I think), but putting them all together in a tightly constrained environment (or even recognizing that the exploit can happen in the first place) takes a ton of skill, resources, and dedication.
- MarkSweep 5y agoStop weird machines! http://langsec.org/occupy/ http://langsec.org/occupy/
- tialaramex 5y agoIn this particular case: If you are Wrangling Untrusted File Formats, you should be doing so Safely, using WUFFS. You can't make this mistake in WUFFS. Your WUFFS image decoder might decode the image incorrectly, maybe Rudolph has a green or blue nose, maybe he's upside down or just a sea of noise, but it can't have a buffer overflow even if you screwed up really badly. For example, any equivalent of the repeated addition numSyms += ((JBIG2SymbolDict *)seg)->getSize(); in WUFFS will get flagged, it clearly could overflow and WUFFS wants you to write code explaining how you're going to prevent that because overflows aren't allowed in WUFFS. This leaves outfits like NSO with nothing much to attack. Sending me pictures of Rudolph with a green nose by "exploiting" a bug in my image decoder isn't very useful, unlike taking over my phone...
- snypher 5y agohttps://github.com/google/wuffs https://github.com/google/wuffs
- shp0ngle 5y agothe problem is, this is an ancient PDF feature from the 90s that nobody has time to write and debug so they just took an open source parser and slapped it in there it’s hard to rewrite PDF parsing to a new language so that everything still works. Especially those weird features that people forgot about.
- deleted 5y ago[deleted]
- khaledh 5y agoTechnically it's not a buffer overflow; it's an integer overflow bug.