3 ms·
Yes, exactly. That's what I was driving at. It's just a logic error, that leaks sensitive information, by virtue of leaking the wrong information. File formats
by _vvhw 4y ago
Yes, exactly. That's what I was driving at. It's just a logic error, that leaks sensitive information, by virtue of leaking the wrong information. File formats in particular can make this difficult to get right. For example, the ZIP file format (that I have at least some experience with bleeds in) has at least 9 different places where a bleed might happen, and this can depend on things like: whether files are added incrementally to the archive, the type of string encoding used for file names in the archive etc.
- woodruffw 4y agoMakes sense! My colleagues work on some research[1] that's intended to be the counterpart to this: identifying which subset of a format parser is actually activated by a corpus of inputs, and automatically generating a subset parser that only accepts those inputs. I think you mentioned WUFFS before the edit; I find that approach very promising! [1]: https://www.darpa.mil/program/safe-documents https://www.darpa.mil/program/safe-documents
- _vvhw 4y agoThanks! Yes, I did mention WUFFS before the edit, but then figured I could make it a bit more detailed. WUFFS is great. The SafeDocs program and approach looks incredible. Installing tools like this at border gateways for SMTP servers, or as a front line defense before vulnerable AV engine parsers (as Pure is intended to be used), could make such a massive dent against malware and zero days.