10 ms·
Here's the writeup: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-d
by Steko 5y ago
Here's the writeup:
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
edit, previous discussion:
https://news.ycombinator.com/item?id=29568625 https://news.ycombinator.com/item?id=29568625
- TheBozzCL 5y agoHoly shit. My relatives have asked me in the past "could this [image|video|other supposedly innocuous file format] be a virus or hack my phone?". I've always told them not to worry. Can't do that anymore.
- shp0ngle 5y agoThere are two different types of attacks. One is fly-by attacks by random viruses and ransomware. For those cases, I would not worry about pictures. Other is when you are targeted by regimes with essentially unlimited budget. In that case yes, the picture can be a spyware.
- vatys 5y agoHow does one know which category they are in?
- iqanq 5y agoIf you are a feminist activist in saudi arabia, I guess you know the deal
- Cyph0n 5y agoIf you are asking, you are probably in the first category, along with myself and the vast majority of people.
- shp0ngle 5y agoYou never really know. But nobody is going to burn zero days on mass surveillance. It’s just for specifically targeted people.
- Spooky23 5y agoAre you or someone you associate with interesting? Negotiate big contracts? Work in aerospace or defense? Have access to inside information about a public company? Have access or are a high level political official?
- itsokimbatman 5y agoThink about who would want to spy on you, what they'd want to know, and how much they'd be willing to spend to know it. If the most they could get out of you was a few thousand bucks from your bank account and maybe your email password, you're probably in the first category. On the other hand, if you have access to highly confidential information (think classified government info or you're literally working on the next iPhone) or are the type of person who makes enemies of spoiled rich oligarchs in despotic nations then you're probably in the second.
- aborsy 5y agoWho will target you if you are working on next iPhone?
- markdown 5y agoChina. Xiaomi, Huawei, Oppo, Honor... there are quite a few Chinese phone brands that would benefit from knowing what Apple are working on.
- throwaway48375 5y agoeveryone
- christophilus 5y agoI don’t know. If I was going to bust a move on, say, Taiwan, it might be handy to have root access to as many computing devices as possible so that I could wreak havoc on my enemy’s communication and banking systems.
- np- 5y agoThe problem is, everyone is in the second category over a long enough time frame. Hong Kongers probably thought the same, but suddenly there were crackdowns, and state actors probably would have loved to have unrestricted access to peoples phones to see if citizens were exercising their “free speech” correctly. Think about Ukraine today, the Russian government would probably love to have a way to compromise millions of Ukrainian citizens’ phones. These people all use iPhones.
- pvg 5y agoThere's classical literature on this: https://www.usenix.org/system/files/1401_08-12_mickens.pdf https://www.usenix.org/system/files/1401_08-12_mickens.pdf
- IncRnd 5y agoThat's terrible advice that is among some of the worst advice that could be given. There are many other types of attacks that are not viral, are not ransomware and do not originate from state actors.
- heavyset_go 5y ago> Other is when you are targeted by regimes with essentially unlimited budget. In that case yes, the picture can be a spyware. If this was the case, exploits would never be published or abused, and jailbreaks wouldn't exist because this logic says that those who find exploits will either disclose them "responsibly" or sell them to a nation-state. If the idea of non-state hackers doesn't bother you, recognize that organized crime is a billion dollar industry and fraud rings would love root access on tons of normal people's devices, including your own.
- schoen 5y agoIn the late 1990s there were a ton of hoaxes about image files supposedly being viruses. Most famously: https://en.wikipedia.org/wiki/Goodtimes_virus https://en.wikipedia.org/wiki/Goodtimes_virus I remember telling lots of people at the time that this was impossible, because images weren't executable code, and viruses spread through running programs, not through viewing images. Unfortunately, this elegant, straightforward distinction didn't hold up over time. :-( https://en.wikipedia.org/wiki/Weird_machine https://en.wikipedia.org/wiki/Weird_machine
- 5co 5y ago
- nomel 5y ago> Unfortunately, this elegant, straightforward distinction didn't hold up over time. :-( I think it was more that it was never true, rather than not holding up in time. ;) The earliest I can find is a vulnerability in Netscape 3.0 (1996), not found until four years later: https://www.openwall.com/articles/JPEG-COM-Marker-Vulnerability https://www.openwall.com/articles/JPEG-COM-Marker-Vulnerabil...
- thrashh 5y agoYou just need a buffer overflow in a file format parser. Thus the distinction has never existed. There has never been such thing as a “safe” format.
- anshumankmr 5y ago>because images weren't executable code I believe that is what the creators of this virus must be relying on. All I hope is that creating this image virus doesn't become common knowledge (cause that we will fundamentally reshape how we interact on social media).
- krisoft 5y ago> All I hope is that creating this image virus doesn't become common knowledge All I hope is that devs start replacing parsers with ones written in a safe language.
- morcheeba 5y agoOne of the earlier iPhone jailbreaks was a tiff image... complicated decompression/rendering algorithms leave room for implementation errors, which can be taken advantage of. https://en.wikipedia.org/wiki/JailbreakMe#JailbreakMe_1.0_(iOS_1.1.1) https://en.wikipedia.org/wiki/JailbreakMe#JailbreakMe_1.0_(i...
- ElFitz 5y agoAt some point it was also used as a way to get a custom firmware onto a PSP. Then modders somehow managed to update the batteries' firmware (cf "Pandora battery") and use that. Sony couldn’t patch it, and it was basically game over for them until they released a new generation of hardware, with motherboards immune to the trick. Fun times.
- Terry_Roll 5y agoThe problem with cpu's is they dont know what instructions are supposed to run in order. Pipeline cache goes a little way towards getting the instructions in order, but ultimately a cpu does not know what instructions it has to run in order for a group of instructions to not be malicious. Think of a cpu like an old human telephone exchange where the operator is plugging in different cables to different sockets and hopefully you get the idea. I'm amazed at the tech giants with all their funding and they still cant build secure operating systems or have the resources to reduce attack vectors within their own OS'es.
- pvg 5y agoWe've gone from 'every OS and device is easily exploitable' to mass market devices/OS pairings where drive-by exploits cost a million dollars.
- saagarjha 5y agoYou should look up Rice's theorem, because what you are suggesting is intractable and has nothing to do with the design of CPUs.
- Terry_Roll 5y agoI wouldnt consider Rice's theorem to be relevant for what I was thinking. Sure all programs have common repeatable elements, like open a file, read/write, close file, so you wouldnt have an instruction or few out of the blue suddenly being run, in effect out of context, but thats whats happening here, the normal instructions that would be required to do a task, suddenly start using instructions that are not required in most cases before resorting back to the rest of the instructions for the original task. Its abit like saying, would you expect some instructions for virtualisation to run if you load a jpg to display on screen? I wouldnt expect instructions for virtualisation functionality to be running in this example. Or would I expect some instructions for encryption to run if I were to load a sound file to play over speakers? No I wouldnt expect that to happen, but thats the sort of thing thats happening here, some instructions not normally associated with a task are occurring, so how do you detect and alert and maybe halt those instructions? There isnt anything in the CPU AFAIK that would pick this up, it would need the OS to act as a co-party to perhaps halt this, and I dont know if the OS or even AV software goes to this extent? At best, you'd have something like a dmesg feed or the Intel Processor Trace (https://news.ycombinator.com/item?id=30110088 https://news.ycombinator.com/item?id=30110088) to get the output of instructions being called (possibly independent of the OS), but like I say I dont know of any OS or AV product that goes to this level of monitoring. Thats where I am coming from.
- retrac 5y agohttps://en.wikipedia.org/wiki/Windows_Metafile_vulnerability https://en.wikipedia.org/wiki/Windows_Metafile_vulnerability Long story short: Windows library routines for handling an obscure, obsolete image format had a parser flaw. Simply rendering an appropriately crafted image via the standard Windows APIs -- whether in a web browser, file explorer, file preview, word processor, anywhere -- resulted in kernel-level arbitrary code execution. Now, we've gotten a bit smarter about this sort of thing since. Both at a high level architecturally (don't process image files in the kernel) and at a lower level (use a language that takes measures to constrain its buffers). But the basic scenario hasn't been entirely eliminated. There could be a parser bug somewhere in your web browser for example that allows a properly crafted input to hijack the browser process.
- bombcar 5y agoWhich is why the only safe way to operate is assume anything that is susceptible to outside data is already compromised - and so run them in sandboxes.
- junon 5y agoYou should read the writeup. This was run in a sandbox. Sandboxes are not silver bullets and too can have bugs.
- thaumasiotes 5y agoThat's not a solution. You're just piping the outside data into your sandbox; it can have bugs too.
- Scoundreller 5y agoThis is why I run a 1-task only Windows VM inside a Linux VM on a Mac. Ain’t nobody ripping through x3 0-days for my chats.
- saagarjha 5y agoIf you're a targeted journalist, they'll go through more than three to get you. Full chains are fairly long these days.
- walrus01 5y agoThere's been buffer overflows/RCE exploits in all sorts of software that can parse images since, well, forever. I remember more than 20 years ago seeing a notice about the embedded Internet Explorer rendering engine in Microsoft Outlook Express having an RCE zero day which could be exploited by simply loading an image in the body of an email. Rich multimedia parsing display systems in messaging apps are a very tempting attack surface for entities such as NSO.
- arunc 5y ago"Cook's egg" is a recommended reading. Summary here (spoilers ahead): https://icdt.osu.edu/cuckoos-egg https://icdt.osu.edu/cuckoos-egg
- canadaduane 5y agoWas "Cuckoo's Egg" autocorrected to "Cook's egg"?
- blackberg 5y agoThat summary sparks interest indeed, thanks for recommending! Just ordered a copy.
- judge2020 5y agoThese exploits are only really an issue for your grandparents and whoever if some large-scale mass hack is happening[^2]. As long as they stay up-to-date, anyone not targeted by nation state actors and not holding millions in cryptocurrency[0] likely has nothing to worry about, as these exploits are better used hacking journalists trying to expose corruption or political opponents running against the incumbent[1]. 0: https://news.ycombinator.com/item?id=30322715 https://news.ycombinator.com/item?id=30322715 1: https://www.seattletimes.com/business/rights-group-verifies-polish-senator-was-hacked-with-spyware/ https://www.seattletimes.com/business/rights-group-verifies-... ^2: For instance, the Coinbase Super bowl ad that was only a bouncing QR code would have been a very interesting way to start WW3 if it were Russia hacking millions upon millions of americans' phones, exfiltrating any potentially sensitive information (company emails, etc) in an instant, and/or destroying the device via some exploit chain that destroys the OS and requires a full firmware factory reset to recover.
- IncRnd 5y agoYou're really cavalier about whether widespread hacks happen. See any of the text message attacks from the past decade.
- rfoo 5y agoExcept we don't live in the past decade anymore. Even though people are still sometimes reluctant to updates ("it only made my device slow!"), We made significant progress on patch distribution. In the past a bug in the SMS stack could be mass exploited and still not getting fixed anytime soon. Not anymore. These bugs cost $10k~$100k now and once you mass-exploit it, they are gone.
- onion2k 5y agoonce you mass-exploit it, they are gone That is only true of exploits that have obvious and visible impacts, right? If an attacker found an exploit and used it to put a rootkit on millions of phones, but did nothing with that rootkit and it had no outward markers, would anyone know?
- masklinn 5y agoImage parsers are complicated and often exposed to untrusted data, they’ve always been a big vector of exploits.
- rasz 5y agoDid you miss https://en.wikipedia.org/wiki/Stagefright_(bug) https://en.wikipedia.org/wiki/Stagefright_(bug) ?
- heavyset_go 5y agoExploits via image libraries have been a perennial threat. A lot of jailbreaks on various devices and consoles over the last 20 years owe their existence to such exploits.
- jack_pp 5y agothey are safe, unless they're being targeted by state actors.
- hliyan 5y agoWow, so basically: 1. iMessage has a feature to send and receive GIFs 2. These GIFs are copied to a specific path early in the message processing pipeline (even before the message is displayed) 3. But the copy code doesn't just copy the GIF. It uses the CoreGraphics APIs _renders_ the image to a new GIF file at the destination path. 4. The code uses the ImageIO lib to guess the image format, ignoring the .gif file extension. So you can trick this code to accept a non-GIF file. 5. You can use the above to invoke one of over 20 image codecs that were not intended to be invoked in this code, including the CoreGraphics PDF parser. 6. CoreGraphics PDF parser has a very specific vulnerability in its JBIG2 image codec. 7. JBIG2 takes an image of text, identifies repeating glyphs and uses that fact for better compression. To avoid confusing slightly differing glyphs in things like images of poor quality prints (think e and é, or 3 and 8), it has a way of applying a diff over each instance of an identified repeating glyph. 8. This logic has an integer overflow bug: the 'number of symbols' variable is a 32-bit integer, which can be overflowed using a carefully crafted file. Now the attacker can can set the buffer for symbols to a much smaller value. 9. Making a long story short, this allows overwriting heap memory, setting arbitrary values in the objects used in the JBIG2 logic. 10. The JBIG2 logic uses AND, OR, XOR and XNOR operations when iterating through these objects (to apply the 'diff' on glyphs). The attacker can craft a file that strings together these logic operations so that it basically forms a software logic circuit. 11. So this exploit basically emulates a computer architecture inside an image codec, which can be used to operate on arbitrary memory! Is that right? If so, this is mind-blowing.
- ironSkillet 5y agoIf a hack can be called beautiful, this fits the bill. How do people come up with these?
- miohtama 5y agoBeing trained in Israeli intelligence corps, moving to civilian life, retaining your spook skills and being funded by Saudi billionaire prince who hates human right activism and criticism.
- 5y ago