12 ms·
RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
- kerng 5y agoA bug like this shows that there is probably no security reviews done at all in the VS Code team. This would be flagged right away in a threat model review. Quite worrying. Also, strange that this doesn't get a bug bounty payout - it's very severe.
- deleted 5y ago[deleted]
- mikotodomo 5y agoI don't get the video https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-codes-remote-wsl-for-fun-and-negative-profit/09-poc1.gif https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-cod... He goes to the hacker website and then calculator opens?
- jml7c5 5y agoA common way to demonstrate an RCE exploit is to make the payload launch calc.exe, implying that you can run arbitrary executables. It's a bit of a meme.
- mikotodomo 5y ago
- moritonal 5y agoCould someone with insight give an estimate for how much you could sell an exploit like this, which let's you RCE a fair bunch of developer machines? It feels that paired with a good blog (ironically about WLS) this could be very profitable, compared to the $0 MS awarded them.
- rabite 5y agoI just asked around, I immediately had someone who I've sold exploits to tell me I could field 45k for a bug like this. There's a lot of conditions to selling exploits -- the biggest being that you don't get to blog about what you sell. But it is real money.
- gostsamo 5y agoJust say "supply chain attacks" and the price can reach millions.
- stonepresto 5y agoYour feeling is correct, although as other comments have mentioned it depends greatly on how you market it and to whom. Probably well above $5-10k though. Bug bounty is good in some respects, but the people who profit the most from it are the companies and platforms. IMO it feels dirty to exploit people’s good intentions and ethics (reporting vs selling) for profits, but that’s corporations for you.
- rfoo 5y agoFortunately, demand for such bugs is pretty low ^, so, $1~2k I guess. ^ this is both a good and a sad indicator, it means the bar of post-exploitation for such a bug (on developers' boxes) is "sufficiently high" that your favorite ransomware gangs are not eager to get on. OTOH it means they have way more "easier" enterprise-y targets...
- FundementalBrit 5y agoI'd have taken a trip down to Buenos Aires and sold it.
- dspillett 5y agoWhile most of me likes the idea of being paid good money for my efforts, or even for doing nothing if I can get away with it, a rather pesky part of me (a nagging entity that calls itself “a conscience”) would take all the fun out of doing it by enabling harm to others (via selling information on possible exploits, for instance). The other blockers of course being that I have neither the skills nor the time to find such flaws in the first place! It is true that there are people out there who do have the skills, and the time, and would be fine with selling their results to third parties, so maintainers (particularly those publishing widely used projects), would do well to treat people who practise safe disclosure with sufficient inducement to keep doing so.
- ackbar03 5y agomeh, if you don't do it someone else will.
- tata71 5y agoIndividual Humanism will return. It's long overdue.
- dspillett 5y agoI prefer to judge others by standards I keep myself, rather than slipping mine towards the lowest common denominator. Both because it is morally right IMO and, I must admit, because I like feeling a little superior.
- nkrisc 5y agoOnly if everyone takes that attitude.
- johnday 5y agoIt is generally held that "Defect" is not the optimal strategy in the Prisoner's dilemma, and that seems to be what you're arguing for here, or something analagous to it. Follow the golden rule.
- SahAssar 5y agoNot making websockets follow the same-origin policy was a mistake.
- willbudd 5y agoI suppose that case can be made, but in this case the direct cause of the vulnerability is the WebSocket server not checking the HTTP Origin header in direct violation of the standard (RFC6455), which is spells out at that doing so is a MUST. I could maybe understand whitelisting localhost and file URLs, but giving a carte blanche -on every single interface no less- is just absurdly negligent.
- kevincox 5y agoThis websocket was also listening on external interfaces so a non-browser client could have sent whatever headers it wanted.
- ravenstine 5y agoIn fairness, couldn't the same things still be accomplished with cross-origin POST/GET requests? Not that there isn't some regretability to not making those strictly same-origin as well.
- Karliss 5y agoIssues like this have been repeated countless times in various IDEs, debugger interfaces and local services using browser as UI. Developers need to stop using network sockets as IPC channels for local services unless browsers significantly increase the restrictions on cross site requests. Similar situation with regular CSRF attacks. And it needs to be opt out not opt in. As long it's a responsibility of developer to implement proper authentication checks for something they consider a local service vulnerabilities like this will keep appearing.
- stefan_ 5y ago> Browsers need to stop connecting to anything other than what's typed into the navigation bar. Yes, indeed!
- Xelbair 5y agooh how i would love this future.
- hdjjhhvvhga 5y agoUnfortunately, the companies that control today's web have a different view, and they are the ones in charge.
- cryptonym 5y agoAt this point of time, I give it 10min before we get a magic_proxy nginx module, then your script src will be /magic_proxy/www.evilthirdpary.com/slow_multi_megabyte_script.js You can still import all nasty third parties required by marketing department, bypassing first party protections and leading to even worse security. Or maybe maintain allow lists, basically that's a Content Security Policy. Future is now old man.
- Pxtl 5y agoAt least then the server has to deal with the security implications of talking directly to the advertiser, instead of pushing the risk wholly to the client.
- 8organicbits 5y ago> Does it fix the issues? Yes. > Do I think there are other security issues here and we can bypass this? Also, yes. > Do I want to spend more time doing free work for a company with a 2.5 TRILLION market cap? Hell, no. Troubling.
- SamuelAdams 5y agoNot really all that troubling, all the author is saying is that he wants to get paid for their work. Either Microsoft or other future vendors can actually honor an established bug bounty program, or the author can sell his findings to the highest bidder. Or the author can simply not spend time and energy finding bugs in the first place.
- oaiey 5y agoHighest bidder is unethical and illegal. But does not change the monetary reality
- artful-hacker 5y agoHow is it illegal?
- rajin444 5y agoPass a law that requires companies to pay black market value for bug bounties. It’s also unethical for big corporations to exploit the US oligarchy to get these fixes for free.
- shukantpal 5y agoThere’s no exploitation going on.
- 8organicbits 5y agoDon't miss the middle statement; the author thinks there are further attacks here, even with the fix. Others can also find and then choose to report/sell at their own discretion.
- nur23kg 5y ago
- magicconch 5y agoKudos to the author for a fantastic write up. The structure made reading it a really pleasant learning experience - a solid table of contents, an up-front summary, and a sensible list of prerequisites and instructions for following along.
- bsenftner 5y agoI've only been using VSC for about 6 months. During my the first week of use, I noted how insecure all the plugins and their communications with the main application were set up. Dismayed, I moving the workstation to an airgapped portion of my environment, and the piece of shit would not work without a net connection. So I use VCE inside a VM now. My career includes working for security companies with sensitive information and documents... VSC needs some serious redesigning with multiple experienced security engineers on the team.
- turminal 5y agoWhy not just use some other editor?
- foobarbaz33 5y agoSounds like he has. VCE, Visual Studio Enterprise
- kube-system 5y agoVisual Ctudio Enterprise?
- bsenftner 5y agoI've been trying several editors, but VSC has the best integrated debugging, after Visual Studio itself - I use the free Visual Studio Community version. I'm primarily a C++ developer, but over the last 6 month have been doing a deep dive on machine learning with Python, and that is why I even bothered with VSC. The available guidance on setting up a Python development environment in VSC is abundant, while the same in Visual Studio IDE is significantly less, with scant troubleshooting support. I tried Visual Studio IDE for my Python work at first, but switched to VSC after issues.
- Jerrrry 5y agoMicrosoft has the best bounty hunter program: go fuck yourself. If you find a way to take over MS accounts, or force email swaps, or even gamertag shanaigans, there is too much money to be made, there is not even a point for a bug bounty. It's like a $40 reward for returning a purse filled with $250k. I agree with OP: no more free bugs.
- jodrellblank 5y agoMake bug bounties pay $250k and people will have their friend inside add some bugs for the outsider to find, and share the payday. Pay-per-bug-found incentivises plenty of counterproductive things as well, especially if we're talking about people who happily sell to anyone on the black market.
- darkarmani 5y agoYou can do that today with blackmarket exploits, so why do you think actual bug bounties will cause this problem?
- jodrellblank 5y agoBecause then you'll be able to do it without needing any black market connections or transactions, which will make it easier, more of it happens above board, there's less to trace or indicate any problem so it's less discoverable, the payment is from a trusted source. Why would making it easier make it happen less often?
- deleted 5y ago[deleted]
- Debug_Overload 5y agoIt's not just Microsoft. What most bug bounties pay isn't even close to the amount you can get from selling it on the black market (assuming you have the right connections). It's why selling exploits to nation states and vendors who work with them is so lucrative.
- turminal 5y ago> Your editor has DRM Lovely
- gigel82 5y agoIf I'm reading this right, it assumes the machine's IP is publicly accessible over the internet; which I'm guessing -even with IPv6- is not the case in 99.999% of cases; who just exposes their development machine directly to the internet with a public IP? Still bad, but not quite as bad as owning from the browser via localhost GET.
- fulafel 5y agoThis guess would be incorrect both in the percentage, and in the assumption that this would be required for exploitability.
- deleted 5y ago[deleted]
- ectopod 5y agoNo, JavaScript running in your browser can connect to it. No remote access required. Of course, if you do allow remote access it is even worse.
- dboreham 5y agoWait, the browser allows random http connections to localhost from JS fetched from any domain?? Edit: after reading tfa, it appears: no it can't , but it may due to browser security vulnerabilities.
- nitrogen 5y agoDo browsers block access to 192.168/16 or 10/8 etc?
- AntonyGarand 5y agoIt does, if the server accepts the connection there is nothing preventing it. This is frequently used by apps which are installed on your machine but are accessed by links, such as zoom and discord. I think Zoom removed its server after receiving pressure[0] about it, but discord still does it: Head to https://discord.com/invite/test https://discord.com/invite/test and it should open your local discord client, or checking the network requests will reveal up to 10 attempted local ports. [0] https://www.zdnet.com/article/zoom-defends-use-of-local-web-server-on-macs-after-security-report/ https://www.zdnet.com/article/zoom-defends-use-of-local-web-...
- 2ion 5y agoIn a sense Microsoft forgot its own learnings. Because of exactly things like this they prevent UWP apps from connecting to localhost by default and make it very annoying to circumvent and from my experience, the circumvention is not exactly a stable setup. So they really don't want you to do that, and somebody thought enough to make it extra difficult. So, they have UWP, all those well thought-out policies, then make an editor ecosystem out of web technology and throw everything out of the window. No surprise from a $T company with more teams than countries on Earth that not everything is coordinated, but they should have a guy with the required knowledge and sensibilities on any major product team. Apps installed from their "store" are relatively safe, but then they put a (extension) store inside their app again, which is unsafe :/
- easton 5y agoApps installed from the Microsoft Store are no longer guaranteed safe, as Win32 apps can be added to the store now and installed via winget. There’s static analysis and they run the installer, but if it does something stupid after the install they can’t automatically detect it.
- withinrafael 5y agoAnd it was unsafe for a few years prior to this event too, with the introduction of Desktop Bridge apps (packaged Win32 hybrid apps running with full trust).
- garren 5y agoDon’t the win32 apps restrict the calls in that subsystem that one can access? I recall looking into this a while back with the intention of leveraging it for an ancient win32/mfc app. I don’t remember the specifics, but I seem to recall that MS restricted or prevented access to a rather substantial subset of win32.
- WorldMaker 5y agoNot anymore. Microsoft gave up on trying to sandbox Windows Store installs for Win32 apps.
- christophilus 5y agoWhat is the best alternative for TypeScript development? My favorite light-weight editor is Kakoune, but it really doesn't have enough plugins for the kind of work I do.
- DangitBobby 5y agoWebstorm is quite good. Better than VsCode, in my opinion. I use PyCharm while working on a Django/React monolith and I would say even that is better for TS than VsCode.
- mrtnpwn 5y agoSublime Text 4 with LSP-TypeScript is really nice. The official package that Microsoft ships with the TypeScript Language Server tends to stop working after a while... I'm not sure why but that's that.
- VPenkov 5y agoProbably one of the JetBrains products, e.g. WebStorm or IDEA.
- symlinkk 5y agoIs this specific to WSL or does it work with other Remote types (SSH)?
- azalemeth 5y agoThe "Your editor has DRM" section alone [0] is enough for me to continue to advocate for a better user-friendly FOSS IDE, in addition to the wonderful giants of emacs & vim, and to avoid the VS Code "kool aid". [0] https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-codes-remote-wsl-for-fun-and-negative-profit/#your-editor-has-drm https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-cod...
- jodrellblank 5y agoVS Code is MIT Licensed - https://github.com/Microsoft/vscode https://github.com/Microsoft/vscode Arguably the MIT license gives you more Freedom than the GPL'd Linux kernel or GNU utilities. Trying to draw a distinction between "evil user-unfriendly Microsoft stuff" and "Holy Saviour FOSS" is not meaningful anymore.
- throw10920 5y agoSome parts of VSCode are MIT Licensed - not all of it, and in particular, parts of the standard VSCode that almost everybody downloads are straight-up proprietary, per the article[1]. [1] https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-codes-remote-wsl-for-fun-and-negative-profit/#your-editor-has-drm https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-cod...
- jodrellblank 5y ago> "Some parts of VSCode are MIT Licensed - not all of it" The source code, the editor are. This is like Oracle releasing a proprietary plugin for EMACS and distributing it on Oracle Linux, and someone saying "this is bad, we need FOSS editors!". That wouldn't make EMACS not-FOSS. (Is it trolling of me to point out that of course the thing people actually want is not the FOSS bit? There are dozens of editors, people want features not ideology)
- throw10920 5y agoEmacs' TRAMP is remote-access like VSCode server - except in addition to being completely open-source, it also doesn't require that you install anything on the server, which ranges from being annoying to a show-stopper in corporate environments. However...I love Emacs, but as much as I hate to admit it, VSCode's out-of-the-box experience is significantly better than even starter kits like Doom and Spacemacs ): VSCode is far more "user-friendly" than Emacs or Vim at this point in time. That's definitely something that can be changed, but let's not delude ourselves...