5 ms·
https://nvd.nist.gov/vuln/detail/CVE-2018-4192 https://nvd.nist.gov/vuln/detail/CVE-2018-4192 https://nvd.nist.gov/vuln/detail/CVE-2019-8601 https://nvd.nist.g
by hinoki 4y ago
https://nvd.nist.gov/vuln/detail/CVE-2018-4192 https://nvd.nist.gov/vuln/detail/CVE-2018-4192
https://nvd.nist.gov/vuln/detail/CVE-2019-8601 https://nvd.nist.gov/vuln/detail/CVE-2019-8601
Remote execution vulnerabilities happen in JavaScriptCore. Tech-savvy won’t save you, all it takes is some malicious ad code or some hacked server providing malicious JS (or media files, etc. etc.)
- newaccount74 4y agoAre there any proof-of-concept exploits for these issues anywhere that people could try out for themselves? I think it would go a long way to convincing people if you could for example visit a website that eg. changes your desktop background when you visit it, to show how dangerous it is to run unpatched systems. There are so many documented vulnerabilities that only apply to certain scenarios, that people (myself included) just think, "Hey, that sounds very theoretical, I don't think it applies in my case"
- saagarjha 4y agoThey’re a bit of a pain to implement but it might be worth doing…?
- newaccount74 4y agoI wonder if they are actually possible. Remote code execution in the javascript engine does sound dangerous, but then you also have to get past address space randomisation, and then you need another exploit to escape the sandbox...
- saagarjha 4y agoRight, all of which get patched every update as well. In theory chaining them together is doable, it’s just effort.
- sph 4y agoI've been asking every chance I get whether these security issues affecting unsupported operating systems are actually being exploited in the wild. Three times I've asked, yet so far, no one has shown any proof whatsoever. Add to that proof of Spectre and Meltdown drive-by exploitation in the wild, today. While I do not condone the use of an insecure version of the OS, herd immunity is an underrated factor. Unless you're targeted, malware developers don't spend too much time on 0.5% market share, just like web developers don't optimise for unknown browsers. Prove me wrong.
- bagels 4y agoWell, it hasn't happened for quite a few years, but it was quite common years ago to get drive by ad malware on up to date systems even. It's the main reason I started turning off JavaScript, and later using ad blockers. I can't imagine it's impossible today.
- cedilla 4y agoIt's the prevention paradox all over again. With Sepctre mitigations rolling out in under a month to almost all PCs, of course there is less incentive to build an exploit. But we know how it was when 90% of PCs were unpatched XP boxes.
- muricula 4y agoWannacry used the exploit from EternalBlue to create one of the most famous ransomware worms in recent memory, and wasn't the only malware to leverage that one exploit: https://arstechnica.com/information-technology/2019/05/eternally-blue-baltimore-city-leaders-blame-nsa-for-ransomware-attack/ https://arstechnica.com/information-technology/2019/05/etern... https://en.wikipedia.org/wiki/WannaCry_ransomware_attack https://en.wikipedia.org/wiki/WannaCry_ransomware_attack Despite lots and lots of POCs, I haven't seen attackers use spectre in the wild yet. Maybe sophisticated actors are using it but they haven't been caught yet, or more likely they just use more traditional and reliable ways to get info leaks. But if traditional info leaks dwindle, they may turn to speculative execution attacks.
- 4y ago
- forgotmypw17 4y agoAdblock is the most effective security application we have today.