4 ms·
Was it even an exploit? I seem to recall reading something about code-signed applets being allowed to load native dlls by design. Which is crazy, one single "tr
by 0x0 3y ago
Was it even an exploit? I seem to recall reading something about code-signed applets being allowed to load native dlls by design. Which is crazy, one single "trust signature" dialog prompt from infecting a system with malware...
- Xophmeister 3y ago> one single "trust signature" dialog prompt Sweet summer child ;)
- 0x0 3y agoI mean I'm sure there were a million exploits that would bypass even the check and prompt, but that doesn't change the fact that it's pretty crazy that native code execution was part of the design with just one small incomprehensible trust dialog.
- withinboredom 3y agoI don't think there was any dialog at all. IIRC. At first, people weren't worried about security. It was just a bunch of us nerds on there. You interacted with real people that didn't seem like they were trying to swindle you. The world still used paper checks for anything big, and credit/debit cards were there, but not like today. It wasn't that uncommon to write a check and ask the shop owner to cash it next week, at least in my poor household. There wasn't "online banking" or "online identities" to steal, so it didn't seem all that important. The worst thing that would happen is you would lose access to a chat handle.
- vbezhenar 3y ago> one single "trust signature" dialog prompt from infecting a system with malware How many dialog prompts are there to launch signed downloaded exe?
- 0x0 3y agoAt least running an .exe should be somewhat obvious to computer literate people. When I saw those signed applet dialog prompts, even as a developer it was not obvious to me that it also meant granting unsandboxed x86 code execution to a .dll/.so from the internet.
- kaba0 3y agoThe sad truth is that executables on desktop haven’t inched much closer to security in the following decades (thankfully mobile did).
- cyberax 3y agoNope, I used an actual exploit, a type confusion bug somewhere within the RMI that allowed to escape the applet's ClassLoader. It then allowed it to access COM objects and basically do everything it needed. The result was a "zero-touch" installation, with seamless login experience. It was a really crazy time.
- 0x0 3y agoWild. So any other website could then do the same thing as you, accessing the hardware key and all...? Did anyone stop to think maybe this wouldn't be the best way to expose a hardware key? I mean, if you care about security at all, which you probably do if you're even bothering with a hardware key...??!?! %-)