3 ms·
Watching the video, they mention that in order for the red team to reach their goal (downloading Google Glass schematics), they had to pivot from the users they
by g_sch 4y ago
Watching the video, they mention that in order for the red team to reach their goal (downloading Google Glass schematics), they had to pivot from the users they compromised with the plasma globe (who were not working on the Glass project) to users on the Glass team. They seemingly did that using an image attached to an email that executed its payload when the email was opened. They didn't elaborate what the payload did, but mentioned that it "captured the user's fingerprint" and enabled them to use that to access the Glass schematics.
Although it sounds much less exciting, this sounds like a much more serious exploit than a compromised USB plasma globe - embedded in an image and requiring minimal user interaction to execute. I wonder whether they identified a novel 0day in a common image parser or something.
- evan_ 4y agoI wondered about that too. My guess is that the image was just a trigger loaded off either a remote server or a local server installed by the exploit so they could know when the user was logged in to their Google account rather than a personal account, which would be off-limits for the exercise. I’m guessing the documentary just glossed over it for brevity.
- peddling-brink 4y agoI have no insider knowledge, but SVGs can contain JS.
- ygra 4y agoNot when rendered in an img element. Well, they can still contain it, but it won't run.