4 ms·
Not just QA; security assurance, code reviews, static and dynamic testing, threat surface analysis, unit testing, and pentesting either didn’t exist or weren’t
by clwg 2y ago
Not just QA; security assurance, code reviews, static and dynamic testing, threat surface analysis, unit testing, and pentesting either didn’t exist or weren’t sufficiently applied.
I have to imagine that this bug has existed for quite some time and I’d be curious to know what other input validation errors they have, considering the amount of untrusted input they evaluate at ring 0 originating from userland.
- lambdaone 2y agoAgain, there are safe ways of doing this. For example, Wuffs exists: https://github.com/google/wuffs https://github.com/google/wuffs At the very least, big money security software companies should be parsing untrusted content with some kind of rigorouly safe approach, not just squirting it through a big pile of C/C++. And don't get me started on the whole concept of undefined behavior in those languages. To quote I. I. Rabi, "Who ordered that?"
- gruez 2y ago>At the very least, big money security software companies should be parsing untrusted content with some kind of rigorouly safe approach the malformed files were updates from crowdstrike itself. It's not exactly "untrusted content".
- kchr 2y agoIt is untrusted data in the sense of files being read from disk that are not part of the signed kernel driver code.
- gruez 2y agoThe files in question reside within C:\windows, which requires admin privileges to write to. If untrusted data can end up there, you're already on the other side of the airtight hatchway[1]. [1] https://devblogs.microsoft.com/oldnewthing/20220907-00/?p=107132 https://devblogs.microsoft.com/oldnewthing/20220907-00/?p=10...
- YZF 2y agoFuzzing... I'd love to hear from an engineer on the project but unfortunately we're likely not to.
- kchr 2y agoHighly unlikely anyone except governments or top-paying corporations with custom-negotiated T&Cs will see a detailed post-portem, unless someone blows the whistle. Would love to read an AmA.