8 ms·
A Tale of Two Pwnies (Part 1)
- donspaulding 14y agoWOW. I read the whole thing, but I was unable to visualize the vulnerability after about the second paragraph describing it. Maybe it's more mundane than I picture in my head, but I would love to look over someone's shoulder as they went through that process.
- jorgem 14y agoSo crazy. I wonder how long it took to come up with that attack? There must have been a ton of dead ends along the way.
- rpicard 14y ago> A teenage hacker who identified himself only as PinkiePie said he spent the past week and a half working on the attack. Source: http://arstechnica.com/business/2012/03/googles-chrome-browser-on-friday/ http://arstechnica.com/business/2012/03/googles-chrome-brows...
- wizzard 14y agoWell, if you start from the last step (I want to load an NPAPI extension because I can gain control from one) and work backwards it seems a little less like stumbling in the dark. I liked the confirmation prompt bug though, that was icing on the cake.
- jorgem 14y agoBackwards... smart!
- tptacek 14y agoWhat's amazing about this bug is that at every step you learn something that makes Pinkie Pie more terrifying while simultaneously making the Chrome security model sound more and more forbidding.
- architgupta 14y agoThe other thing I wonder about is that in 2040, will we be still worrying about buffer overflows?
- tptacek 14y agoI really doubt that we'll be using programming environments where memory corruption is possible in 2040.
- adrusi 14y agosomeone's gotta write the kernels though, I can't think of any way to write kernels or compilers where memory corruption is impossible.
- sixcorners 14y agoDidn't Microsoft make an experimental kernel with managed code?
- reginaldo 14y agoIndeed. It is the Singularity Research OS. Links: http://en.wikipedia.org/wiki/Singularity_(operating_system) http://en.wikipedia.org/wiki/Singularity_(operating_system) http://research.microsoft.com/en-us/projects/singularity/ http://research.microsoft.com/en-us/projects/singularity/
- zobzu 14y agoNote that managed code is just one feature of Singularity. They have many other important concepts (like SIPs). Plan9 ain't bad either. There's also different C# clones (that aren't based on Singularity)
- zurn 14y agoI wonder if SIPs are new or did eg the various Java OSes or the Burroughs ALGOL based system do something similar?
- picklefish 14y agoI'd love to see a writeup from Pinkie Pie on the steps and tools he used to find these bugs. Reversing write-ups are always entertaining to read.
- moistgorilla 14y agoThis really takes you into the mind of a hacker(the malicious kind). Judging from what I saw it seems they combine a ton of small exploits to produce a major security breach. The amount of understanding of the underlying system you need to have in order to put these exploits together is mind boggling. What do we do against people like this?
- TheBoff 14y agoPay them to find the bugs!
- skeletonjelly 14y agoJust don't let them run out of bugs to find, or get bored :P
- wtracy 14y agoWhat's the problem if they run out of bugs to find? Would that not imply that there are no exploits left to be made?
- skeletonjelly 14y agoBecause if they get bored, they'll find other things to exploit/break. It's in their nature.
- saurik 14y agoThen, by definition, you would not have run out of bugs.
- JamesLeonis 14y agoIMHO, as Pinkie demonstrated, there isn't anything foolproof that you can do against a malicious hacker. Having sponsored and/or incentives for white hat hackers to find and report exploits seems to be the best answer. If this stance were adopted into the wider software development community, would it turn more black hat hackers into white hats? EDIT: grammar
- Jun8 14y agoSo for about $120K+ they had more than 16 significant bugs discovered in Chromium. That's really cheap!
- mark-r 14y agoIf you don't have a young girl you might not appreciate the link between "Pinkie Pie" and "Pwnie": http://mlp.wikia.com/wiki/Pinkie_Pie http://mlp.wikia.com/wiki/Pinkie_Pie
- CrazedGeek 14y agoSomewhat OT, but the show has a fairly sizable periphery demographic (males 13-35), which I would guess the hacker considers himself a part of. More information: http://knowyourmeme.com/memes/subcultures/my-little-pony-friendship-is-magic http://knowyourmeme.com/memes/subcultures/my-little-pony-fri...
- btown 14y agoPinkie's not the only brony hacker either. Consider this Rainbow Dash fan: http://www.reddit.com/r/IAmA/comments/sq7cy/iama_a_malware_coder_and_botnet_operator_ama/ http://www.reddit.com/r/IAmA/comments/sq7cy/iama_a_malware_c... ... and in general, there are a plethora of bronies scattered across the startup world and CS academia (full disclosure: myself included).
- Zirro 14y agoOr perhaps not: https://secure.wikimedia.org/wikipedia/en/wiki/My_Little_Pony:_Friendship_Is_Magic_fandom https://secure.wikimedia.org/wikipedia/en/wiki/My_Little_Pon... :) Considering that he is a teenage hacker, it's likely that he is a Brony himself.
- lotharbot 14y ago> "If you don't have a young girl" Most of my recent MLP exposure is through my 20-something brother. Apparently he's in one of the larger demographics for the modern show. See http://en.wikipedia.org/wiki/My_Little_Pony:_Friendship_Is_Magic_fandom#Brony http://en.wikipedia.org/wiki/My_Little_Pony:_Friendship_Is_M...
- pilif 14y agoIn the end it all boiled down to old-style plugins. All the exploits were used to finally install and run an old-style NPAPI plugin. Just like ActiveX, these are binary code that usually runs outsidE of any sandboxing due to compatibility reasons. With NaCL or just the advances in HTML and related technologies, this kind of plugin really should have outlived its usefulness by now and maybe it's time to drop support - at least support for all plugins but a few whitelisted ones from the older ages. Like Flash and maybe QuickTime (though both have a terrible security track record). Though considering the persistence of piling up bugs that was happening here, for all we know, there would have been a different exploit somewhere else that could have worked even without NPAPI. It would just close one more attack surface.
- aboodman 14y agoWait until you see the other one. There are a surprising and depressing number of ways to get a browser to run native code on legacy operating systems. Yes, plugins should go away. No, that won't stop this kind of thing :/.
- Arelius 14y agoLet's be fair here, This particular bug used an NPAPI installation to finally get full access, but there many other significant breaches of security previous to this, it seems that the final step, was likely one with the most potential vulnerabilities, with NPAPI just being the easiest to install the payload.
- jtchang 14y agoIt is scary that once you have a foothold it just becomes a matter of time until someone figures out how to use it to piggyback on to more unrestricted space.
- 0xOXO 14y ago"low level interface to the GPU command buffers" This sounds cool. Is this something that will be accessible to an interested Chrome user?
- thereason 14y ago"a low level interface to the GPU command buffer" This sounds cool. Is this a standard feature in Chrome?
- obtu 14y agoIt's available for extensions I think (there's also the higher-level WebGL which you must be aware of), and requires whitelisted graphic drivers. As you can see, graphic acceleration offers a huge attack surface (memory-unsafety in C++ code, plus logic bugs at highly privileged levels like graphic drivers, firmware, and the hardware itself). Some of these layers realistically won't be protected until they have proper IOMMU support.
- tobyjsullivan 14y agoJust... sick! Wow. Speechless.
- cnbeuiwx 14y agoThis is a real hacker. I wish I had this kind of passion and intelligence myself. :)
- samratashok 14y agoThat looks awesome !!