5 ms·
The majority of CVEs are due to memory exploits. For C/C++ code that holds true across companies and OSs Microsoft says 70% https://www.zdnet.com/article/micro
by overthrow 3y ago
The majority of CVEs are due to memory exploits. For C/C++ code that holds true across companies and OSs
Microsoft says 70% https://www.zdnet.com/article/microsoft-70-percent-of-all-security-bugs-are-memory-safety-issues/ https://www.zdnet.com/article/microsoft-70-percent-of-all-se...
Google says 70% https://www.chromium.org/Home/chromium-security/memory-safety/ https://www.chromium.org/Home/chromium-security/memory-safet...
- NikolaNovak 3y agoI don't know if this is pedantic, but op indicated "attacks" not "vulnerabilities". I would not be surprised if statistics in vulnerabilities are different than statistics in realized attacks?
- overthrow 3y agoIf there's a difference I'm open to someone citing a source quantifying it, but I won't quite be convinced by unsourced blanket generalizations that go against common wisdom
- ecdavis 3y agoThis page is informative: https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-publications/notifiable-data-breaches-report-january-to-june-2022 https://www.oaic.gov.au/privacy/notifiable-data-breaches/not... > Just over half (54%) of cyber incidents involved malicious actors gaining access to accounts using compromised or stolen credentials. My experience has been that most attacks are not that sophisticated and tend to target poor practices within organisations.
- FreakLegion 3y agoA majority of CVEs are memory exploits. A majority of attacks don't use CVEs. It's a common misconception among people on HN who don't work in the field.
- Genbox 3y agoI work in the field and I'm not entirely sure about the cardinality of types of attacks. On one hand, there are password spaying, RDP bruteforces, email attachments, social engineering etc. On the other we have BlueKeep, ZeroLogon and the tons of RCE present in VPNs (looking at you PulseSecure), Routers, and Firewalls. I would say that breaches often are related to RCE that ultimately derives from buffer exploitation. They are notoriously difficult to detect with forensics techniques, so they might not be discovered and tracked.
- _8j50 3y agoYou're guessing I think. Phishing of some sort is by far the most reliable and used method. CVEs that get exploited are rarely using memory exploits but they do happen and affect companies and people that refuse to update their stuff to the most part. There is just rarely the need to spend time to develop memory exploits because on every consumer OS there is some sort of memory-safety protection. At least DEP or ASLR unless you get lucky and and the software or shared libs have all that disabled or reliable rop gadgets are found.
- Genbox 3y agoI'm not making general claims about the use of memory exploitation - only questioning the statement that they are not widely used. With more than 500 forensics cases with my name on it, and a substantial amount of them being RCE based, I'd say it is more than just guessing. There is no need to spend time on developing a exploit when you can find hundreds new ones every month on GitHub. DEP and ASLR are also not used in embedded devices where memory management in the firmware is atrocious.
- selfmodruntime 3y agoASLR and other hardening practices are also not used in old machines on your network everyone forgot about
- _8j50 3y ago