5 ms·
As a software engineer I still don't understand how this is even possible. What kind of logic behind a URL preview can bypass everything? I think companies lik
by stunt 5y ago
As a software engineer I still don't understand how this is even possible.
What kind of logic behind a URL preview can bypass everything? I think companies like NSO Group are just finding backdoors not software bugs.
- dpacmittal 5y agoAFAIK, they are exploiting vulnerabilities in image and video decoders
- tebbers 5y agoYep it’s usually that or body parsers, that sort of thing.
- strstr 5y agoFrom what I recall the stagefright vulnerability might be a good example.
- ajconway 5y agoThere are software engineers who sometimes write code that’s not perfect.
- xvector 5y agoSo frustrated with the slow adoption/transition to memory-safe languages.
- petalmind 5y agoTrue. Perl exists for more than 30 years already.
- giantrobot 5y agoAda throws out its back with a chuckle.
- sva_ 5y agoThis one is a good example: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html?m=1 https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i... Really worth the read, it was quite eye-opening. > JBIG2 doesn't have scripting capabilities, but when combined with a vulnerability, it does have the ability to emulate circuits of arbitrary logic gates operating on arbitrary memory. So why not just use that to build your own computer architecture and script that!? That's exactly what this exploit does. Using over 70,000 segment commands defining logical bit operations, they define a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations. It's not as fast as Javascript, but it's fundamentally computationally equivalent. > The bootstrapping operations for the sandbox escape exploit are written to run on this logic circuit and the whole thing runs in this weird, emulated environment created out of a single decompression pass through a JBIG2 stream. It's pretty incredible, and at the same time, pretty terrifying.
- gfd 5y agoHoly shit
- d0mine 5y agoIt is so improbable and complicated that it is easier to believe that it is just a parallel construction to hide the fact backdoors are used.
- Gigachad 5y agoIt doesn’t seem all that unrealistic. These companies buy and research every single bug they can get for iOS and eventually you have enough that you can glue them together in to full exploits. When you have enough funding, this stuff becomes realistic.
- scoopertrooper 5y agoNever underestimate the extremes computer science types will go to in order to prove a point.
- jeroen 5y agoFrom the article: > In December, security researchers at Google analyzed a zero-click exploit they said was developed by NSO Group, which could be used to break into an iPhone by sending someone a fake GIF image through iMessage. And the thread from back then: https://news.ycombinator.com/item?id=29568625 https://news.ycombinator.com/item?id=29568625 That Project Zero blog post lays out the details under the "One weird trick" header.
- bawolff 5y agoURL preview is a pretty big attack surface, you have to fetch over network using complex protocols, parse the result for a variety of formats, and then render it.
- 55555 5y agoRight. Showing an “image preview” for myriad file types means executing them, essentially, and perhaps on buggy code.
- phendrenad2 5y agoI like how all of the replies to this are basically "No they exploited things that were already there". Yeah, and the things that were already there were written by..? Robots? Monkeys? Oh, employees. Got it. rolls eyes I think it's completely reasonable to assume that any OS vendor has enemy spies working for them. How could they not?