11 ms·
CWE Top Most Dangerous Software Weaknesses
- dlor 3y agoIt's somewhat disheartening as a software developer focused on security that the top four elements are still: * Out-of-bounds Write * Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') * Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') * Use After Free
- tumdum_ 3y ago"But modern c++ is safe, preventing all those errors is as easy as not making them!..."
- deleted 3y ago[deleted]
- littlestymaar 3y agoIn fairness, only 2 of those 4 are actually memory-related.
- tialaramex 3y agoI agree that in principle the neutralization bugs aren't something C++ is necessarily making worse than, say, Python. But it'd be fascinating to see a study to figure out whether C++ programmers make these mistakes more often, or less often, or roughly the same. An argument for more often: C++ is so complicated, maybe you're too busy with other problems to address the neutralization issue An argument for less often: C++ teaches you to be careful and check everything to avoid nasty outcomes so that carries over to neutralization
- tumdum_ 3y agoIn fairness, only C/C++ of all the currently commonly used languages can have half of the 4 top dangerous software weaknesses.
- littlestymaar 3y agoJavaScript routinely has the other half of the top4.
- tatersolid 3y agoSo do C and C++ when used in web or database applications. So they get 4/4
- deadletters 3y agoAnd both have existing tools to find those bugs that people often just don't use.
- pjmlp 3y agoSince 1979 with the invention of lint by Stephen Johnson at Bell Labs. https://en.wikipedia.org/wiki/Lint_(software) https://en.wikipedia.org/wiki/Lint_(software)
- UncleMeat 3y agoStatic analysis as a bugfinding tool has proven to be insufficient, especially for large C++ binaries and JS programs. Both languages are nightmares for precise and scalable analysis. Coverity exists. They've got a great product. But it doesn't solve the problem.
- pjmlp 3y agoIt doesn't solve everything, it solves even less when it isn't used.
- UncleMeat 3y agoOf course. But these issues will remain near the top of the list indefinitely if people just leverage traditional analysis tools. I love static analysis. I did my PhD in it. But we'll still be talking about use after free in 2073 if we just try to chase higher K in our analysis implementations.
- pjmlp 3y agoNaturally static analysis alone doesn't fix use after free in all possible cases, however it already does fix several of them when the analyser can see everything on the existing source code. The main issue is the community sub-culture of not adopting tooling as it isn't perfect 100% of the time. Many of the C++ security conscious folks end up being polyglot, as this subculture eventually wears one out.
- citrin_ru 3y agoIs there some authoritative source for what is considered modern C++ and what is old? Most projects I've seen use a wide mix of C++ features of varying age. If you use some C++23 futures it would not make it modern if you still use C++98 features you not supposed to use.
- zabzonk 3y agonot authoritative, but the really big c++ change was with c++11 - changes after that have been important, but perhaps more or less transparent to the average c++ user. and compiler support for c++11 is very good.
- SubjectToChange 3y ago“Modern C++” is not necessarily tied to any specific standard, it is more a collection of ideas and philosophies. Although if I had to pick I’d say it really started with C++11.
- tumdum_ 3y agoNo, there's no such authoritative source - depending on context C++ fans will mix and match what is 'modern'. It's somewhat similar to the C/C++ split. When it is convenient it's "C/C++" because "you can easily migrate your old C codebase to C++". But in other situations it's "C++", because C is old and more error prone and "we no longer manipulate raw pointers".
- pjmlp 3y agoOriginally it refers to what was already possible in C++98, when one leaves behind the legacy ways of coding C with a C++ compiler. Started with the publishing of "Modern C++ Design" from Andrei Alexandrescu in 2001. https://en.wikipedia.org/wiki/Modern_C%2B%2B_Design https://en.wikipedia.org/wiki/Modern_C%2B%2B_Design When ISO C++11 came to be, many re-used the term to mean C++11 or higher. Given that many keep updating this to mean more modern versions, a well known developer in the community (Tony Van Eerd) has made the joke of that by C++17 time we were in Postmodern C++. https://www.youtube.com/watch?v=QTLn3goa3A8 https://www.youtube.com/watch?v=QTLn3goa3A8 No idea what kind of modernism to call C++23, when C++17 was already postmodern, maybe Revivalist C++. However it basically comes back to Andrei Alexandrescu's original ideas of programming in C++ as its own language, leave the C ways and pitfalls of resource management behind, learn to embrace a modern language for systems programming. I should also note that there are developers against this philosophy, they advocate that the C++ as understood by CFront is what one should care about, thus Orthodox C++ movement was born. https://gist.github.com/bkaradzic/2e39896bc7d8c34e042b https://gist.github.com/bkaradzic/2e39896bc7d8c34e042b
- anonzzzies 3y ago> mproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') This is often ignored as it simply takes too much time and it often does not hurt much as it’s ‘internal’ (to the company using the saas or whatever).
- deleted 3y ago[deleted]
- mattgreenrocks 3y agoOur industry is ageist and anti-intellectual. These are the symptoms of those.
- lusus_naturae 3y agoMaybe not ageist, but I do think it's easier to get younger people to work slavishly and pay them relatively less (on average, not everywhere pays like Bay area).
- ChuckNorris89 3y agoIt's easy because there has never been a greater backlog of junior candidates trying to break into the industry.
- p-e-w 3y agoWhile I agree that the software industry suffers from ageism and anti-intellectualism, these vulnerabilities are actually the symptoms of elitism, cargo culting, and traditionalism, which it also suffers from.
- geodel 3y agoAgeist against old people? young people? middle-age people? I see at least these 3 categories are facing age related issues.
- poiuyt098 3y agoCould be worded as Low barrier to entry and highly compensated. Kids get into it just by having the tenacity to do whatever it takes to make it chooch. It's all that counts.
- waihtis 3y agoThe gap from knowing what a CWE is and actually knowing, on code level, how it manifests and how you avoid these things is very large. Given how much the software industry has grown in the past 10 years it's not particularly surprising.
- tialaramex 3y agoTwo of those four are things there's no need to make easy to do by mistake, but two popular programming languages choose to do so anyway and they reap the consequences. Actually the SQL one is arguably in that category too, to a lesser extent. Libraries could, and should, make it obvious how to do parametrized SQL queries in your language. I would guess that for every extra minute of their day a programmer in your language must spend to get the parametrized version to work over just lazy string mangling, you're significantly adding to the resulting vulnerability count because some of them won't bother. Bonus points if your example code, which people will copy-paste, just uses a fixed query string because it was only an example and surely they'll change that.
- jiggawatts 3y agoI feel there would be some value in SQL client libraries that just flat out ban all literals. I know it's the nuclear option, but decades of experience has shown that the wider industry just cannot be trusted. People won't ever change[1], so the tools must change to account for that. [1] Unfortunately, LLMs learned from people... so... sigh.
- p-e-w 3y ago> and actually knowing, on code level, how it manifests and how you avoid these things You avoid them by using tools that make it difficult or impossible to introduce such vulnerabilities to begin with. Such as modern, memory safe programming languages. For many decades, carpenters have been educated about table saw safety. But what finally stopped thousands of fingers getting chopped off every year was the introduction of the SawStop, and similar technologies. Safety is a matter of using the right tools, not of "taking better care".
- akmittal 3y agoHow many of these rust can solve? (Not in use rust for everything bandwagon, genuinely curious)
- dgb23 3y agoJudging from my limited experience the first and fourth are either caught by the compiler or at least result in a panic in some cases. The middle two are out of reach of a typical PL or type system (there are exceptions like Ur, but I don't think it's adopted widely). It's a problem that is typically solved via libraries and Rust is not unique in terms of providing safe libraries around generating SQL or HTML.
- speedgoose 3y ago2 of the 4 listed.
- jacquesm 3y agoIt could, but it will be decades before Rust adoption is where C/C++ is today so in the meantime it would be nice to see some other, more practical and short term solution to these problems. Otherwise I can predict the the top 4 at least 50% for a decade ahead.
- pjmlp 3y agoHence why all major OS vendors are embracing designs with hardware memory tagging, that is the last frontier from possible mitigations.
- jerf 3y agoWith a bit of creativity, you can use static typing systems to at least slant the table in your favor with SQL, HTML, and in general, structured text output. It's hard to completely ban string concatenation because you will eventually need it, but you can make it so doing the right thing is easier than the wrong thing. However, existing libraries for statically-typed languages often don't do the work or apply the creativity and end up roughly as unsafe as the dynamically typed languages. It's a bit of a pet peeve of mine.
- throwawaaarrgh 3y agoIt's somewhat disheartening as a security enthusiast that people only focus on "popular" security bugs and ignore the rest. The other top 21 bug classes aren't as "cool" but they will let me hack your app just the same.
- HideousKojima 3y agoSure, but SQL Injection will let a script kiddie steal and/or drop your entire poorly configured production DB.
- rainonmoon 3y agoIt also provides several paths to RCE depending on the environment, not just exfil.
- Mountain_Skies 3y agoSQL Injection is weird because it's been known for so long and modern frameworks usually have so many ways of avoiding it by default, that's one has to go out of their way to create an injection vulnerability, but it still happens often with greenfield code.
- valenterry 3y agoThen ask yourself: how much have you done to prevent people choosing the wrong programming language? Because the PL has such a major influence, it's by far the most low hanging fruit to tackle those many of those issues.
- dlor 3y agoPersonally? I've done quite a bit here although there's always more. I worked at Google to fund Rust development internally and externally, helped sponsor the work that eventually led to getting Rust adopted in the Linux kernel, and now run a company that's building a new Linux distribution that prioritizes shipping code written in memory safe languages. https://security.googleblog.com/2021/02/mitigating-memory-safety-issues-in-open.html https://security.googleblog.com/2021/02/mitigating-memory-sa... https://www.chainguard.dev/unchained/building-the-first-memory-safe-distro-wolfi https://www.chainguard.dev/unchained/building-the-first-memo...
- valenterry 3y agoOh awesome! Then I take off my hat. :-)
- synergy20 3y agofor 1 scan all the code base and warn any use of strcpy/strncpy/etc and replace them with snprintf, no APIs without length argument shall be allowed. for 4 the static analyzer should help, and, also set your pointer to NULL immediately after free too(for double free)
- UncleMeat 3y agoStatic detection of UAF is grossly incapable of actually protecting real C++ applications. It can find some bugs, sure. But a sound analysis is going to just throw red all over a codebase and get people to disable it immediately. Changing everything to take lengths is definitely a good change - but challenging to retrofit into existing codebases. Apple has a neat idea for automatically passing lengths along via compilation changes rather than source changes, but if you want to do things in source you have to deal with the fact that there is some function somewhere that takes a void*, increments it locally, reinterpret_casts it to some type, and then accesses one of its fields and you've got a fucking mess of a refactor on your hands.
- actualwitch 3y ago> top four elements are still Use after free is actually gaining popularity, up 3 since last year.
- pulse7 3y agoHere are Language-Specific ones: 1. CWE-787 Out-of-bounds Write: C, C++, Assembly 4. CWE-416 Use After Free: C, C++ 7. CWE-125 Out-of-bounds Read: C, C++ 10. CWE-434 Unrestricted Upload of File with Dangerous Type: ASP.NET, PHP, Class: Not Language-Specific 12. CWE-476 NULL Pointer Dereference: C, C++, Java, C#, Go 15. CWE-502 Deserialization of Untrusted Data: Java, Ruby, PHP, Python, JavaScript 17. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer: C, C++, Assembly 21. CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'): C, C++, Java 23. CWE-94 Improper Control of Generation of Code ('Code Injection'): Interpreted
- dgb23 3y agoPHP is uniquely vulnerable to things like XSS and others on that list, because it does escape strings that are used in templating. Escaping by default has become a standard practice with HTML templating languages, see the Go html template standard library for a very detailed breakdown of what is escaped where. More modern PHP frameworks like Laravel provide their own templating solution in part because of this. But the vast majority of websites run on default PHP templates, so it's not surprising that these kinds of vulnerabilities are so high up in the list.
- jacquesm 3y agoLaravel has had their own share of XSS issues with their Blade templating engine. The whole problem is that you mix code and data, and that third party resource loading is 'on' by default in browsers, especially for scripts and things that can embed scripts. This is not something you can fix once and for all at the library level.
- Xeamek 3y ago>12. Null pointer deref. In java you'll get an exception, while in C you might dissapear your cat. Those 2 are quite incomparable when talking about "dangerous-ness" of a mistake
- jiggawatts 3y ago
- heelix 3y agoMitre really lost a lot of respect with CVE-2016-1000027. Every few weeks a warning that any SpringBoot 2.x project has a CVSS 9.8, which causes all sorts of heartache for those of us bound to CVE remediation. Every blasted security tool reports this one. Spring reviewed and rejected, as did our very, very large organization. Comically, this has become the CVE we use to see how our tools allow us to white/black list entries. Thank god Spring dropped this interface in the Framework 6.x / Boot 3.x release, and the end for non-commercial support is this year for the old stuff. https://github.com/spring-projects/spring-framework/issues/24434 https://github.com/spring-projects/spring-framework/issues/2... https://github.com/advisories/GHSA-4wrc-f8pq-fpqp https://github.com/advisories/GHSA-4wrc-f8pq-fpqp
- stusmall 3y agoWhat would you rather? It seems to make sense to rate these with such a high CVSS. All auditing tools I know of have a way to whitelist CVEs to say either "We've looked into this and it doesn't impact us" or "We are willing to accept the risk". From your post it sounds like you in the first camp, but others might not be and need those notifications. RCE via deserilaization seems valid 9.8 even if it requires the developer to use less common APIs or using them in strange ways. In the bug they have a comment that the documentation warns about these API but that doesn't really impact a CVSS score. Am I missing something about this specific CVE on why you think its unfair?
- gemanor 3y agoI'm really waiting to see all those shift-left startup founders that will craft a new world of developer-oriented products from this list. IMHO, the real way to look at it is how we can influence developers (by choosing the suitable languages, platforms, architectures, etc.) and then measure them after they find the vulns. From the optimistic side, it looks like the safest language to write an app today with is TypeScript.
- rtev 3y agoTypescript applications suffer from many of these vulnerabilities. JS apps have a specific class of critical vulnerabilities as well, prototype pollution. If I had to write a web application with security in mind, I personally would pick Python. It’s possible to make mistakes in any language though, and the environment an app is deployed in can independently introduce many vulnerabilities.
- gemanor 3y agoWhen I wrote typescript, it was half a joke as a result of the language ranking in one of the comments. As you said, the most important factor is the platform, not the language itself. Writing the software in a language that run well on the platform you aim for, is the right decision.
- amelius 3y agoIs anyone using Valgrind even anymore these days? I've noticed that using Valgrind on Python systems is almost impossible because most modules have not been built with Valgrind in mind and thus you get swamped in noise. I suppose the same is true for any large system that uses many different third party libraries.
- gavinhoward 3y agoAbsolutely. I enable Valgrind on every default debug build of mine. It's my favorite tool. I have even made it recognize my custom allocators and report bugs with them too. When combined with my second favorite tool, AFL++, I have a good shot at eliminating most memory bugs. AFL++ finds paths through the software, and I run every single one of those paths through Valgrind. It's beautiful.
- deadletters 3y agoASan is better for finding memory corruption afaik
- amelius 3y agoOk. But I'm guessing it has the same problems. I.e., if half your libraries/modules have never seen it, then you'll get a lot of noise. Happy to be proved wrong.
- deadletters 3y agoThe compiler can't add checks into code it hasn't compiled. External modules, unless they are doing weird things which you do want to know about, should not generate ASan reports... on Linux.
- TheNewAndy 3y agoI use valgrind regularly, and prefer it over asan. asan will result in a faster executable which is nice, but I far prefer valgrind's output than asan's (this might be preference, but I find it to be clearer), and various things break when building with asan so I never make it default. Being able to valgrind stuff without recompiling is very convenient. I'm also not sure if asan has an equivalent to --leak-check=full
- BoppreH 3y agoAside from Memory Management, there's another general category that always comes up in these lists, but is not talked about much: in-band signaling (i.e., "Strings are Evil"): - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (#2) - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (#3) - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (#4) - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (#8) - Improper Neutralization of Special Elements used in a Command ('Command Injection') (#16) - Improper Control of Generation of Code ('Code Injection') (#23) All of these came from trying to avoid structured data, and instead using strings with "special characters". It's crazy how many times this mistake has been repeated: file paths, URLs, log files, CSV, HTML, HTTP (cookies, headers, query strings), domain names, SQL, shell commands, shell pipelines... One unescaped character, from anywhere in the stack, and it all blows up. One could say "at least it's human-readable", but that's not reliable either. Take files names, for example. Two visually identical file names may map to different files (because confusables[1] or surrounding spaces), or two different names map to the same file (because normalization[2]), or the ".jpg" at the end may not actually be the extension (because right-to-left override[3]). So the computer interpretation of a string might be wrong because a special character sneaked in. And even if everyone was perfectly careful, the human interpretation might still be wrong. For the sake of the next generations, I hope we leave strings for human text and nothing more. [1] https://unicode.org/cldr/utility/confusables.jsp https://unicode.org/cldr/utility/confusables.jsp [2] https://developer.apple.com/library/archive/qa/qa1173/_index.html https://developer.apple.com/library/archive/qa/qa1173/_index... [3] https://krebsonsecurity.com/2011/09/right-to-left-override-aids-email-attacks/ https://krebsonsecurity.com/2011/09/right-to-left-override-a...
- Therenas 3y agoWhat‘s the alternative though? For URLs for example, would you have to put a JSON structure into the browser? That‘s obviously not going to happen.
- BoppreH 3y agoSure, most of these decisions are too entrenched to be fixed. But yes, URLs should have been structured. We already see paths rendered with breadcrumbs, the protocol replaced with an icon, `www` auto-inserted and hidden, and the domain highlighted. If that's not a structure, I don't know what is. By cramming everything into the same string, we open ourselves to phishing attacks by domains like `www.google.com.evil.com`, malicious traversal, 404s from mangled relative paths, and much more.
- matt2000 3y agoIt should be considered a failure of our profession that after all these years the number 1 issue is still out of bounds write, a memory safety issue. In any true engineering profession a failure of this sort would be unacceptable, but in ours it's tolerated and explained away as a necessary byproduct of certain tools. How much personal information has been compromised due to these low standards? How many people put at risk? It's shameful.
- pixl97 3y agoSo you want to be a licensed engineer to write software?
- timbit42 3y agoThis will eventually happen.
- 0xbadcafebee 3y agoIn any true engineering profession, we would still be using C, but with big orange safety vests on.
- _8j50 3y agoCSRF higher than improper auth? Yeah...don't think so.
- timewasterthrow 3y agoWordle sold for a $1M+ and put all the solutions for the future games into the javascript file. Security is important, but its a spectrum.