15 ms·
Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4
- jrpelkonen 2y agoI feel sorry for the maintainers having to spend their energy disproving the validity of these AI generated reports. Daniel Stenberg blogged about this issue earlier: https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/ https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-f... Open source burnout is already real, I hope the volume of the AI slop security reports stays manageable.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- dathery 2y agoI really like his quote: "a well-formed crap report is harder and takes longer to discard". I think that cuts to the core of why people feel betrayed when they suspect they're being fed unlabeled AI content. You see the well-formatted paragraphs, the precise explanations, and you naturally extend a bit more effort in reciprocation. There have always been junk bug reports, but they used to look like what they were.
- bawolff 2y agoWell i agree, in my experience in the past, lots of reports that looked like junk reports were actually real. I've seen lots of security reports with nonsensical explanations, very broken english to the point you can't follow, and then you run their PoC and it shockingly works. Triaging security reports is exhausting and very hard.
- Moru 2y agoA requirement for new bug reports: You must write unitelligible with werid spellin and less understend able lenguish. Try copy that, ai! Z)
- thr3000 2y agoIOW, older heuristics (meant to screen out below par human work) no longer function. Newer AI-specific heuristics are needed. Which is precisely what we're all developing, often without realizing. Unfortunately there's a bit of a perverse feedback loop in that Pinocchio wants to be a real kid.
- tedunangst 2y agoI can kinda understand the motive for carpet bombing an issue tracker with AI slop hoping for a hit, but then to whine about unprofessional responses is really too much. Time to unplug the chatbot.
- BostonFern 2y agoThe complaint sounds AI-generated as well, like the rest of the comments from that user.
- bluGill 2y agoIt sounds like a non native English speaker to me. I've worked with many non natives and some speak like that. Of course they also have enough self awareness to know they don't speak good English - some of them with much effort gotten good in a few years.
- bragr 2y agoNot to mention that the first couple of responses were very professional. At some point you just have to call a spade a spade, or not suffer fools, or whatever expression you prefer.
- deleted 2y ago[deleted]
- doctorpangloss 2y agoThat's Claude for you.
- mort96 2y agoI also understand the "motive": money. If you can spam enough maintainers with bullshit vulnerability reports, there's a chance you'll hit something real or trick a maintainer and get a pay-out.
- nikanj 2y agoOr you can use your track-record of discovering CVEs as a stepping stone to a cushy infosec job
- lanstin 2y agoWow, in the future we will point to this bogosity and say it is why we can't have good things.
- kseifried 2y ago[flagged]
- Adachi91 2y agoI wholeheartedly side with Bagder here. I felt his response in my soul. Even before AI, everyone wants to report a small problem that could be completely insufficient and with mountains of those reports piling on, it becomes increasingly difficult to find REAL issues being reported, by non-technical users who can't do proper PR's.
- CJefferson 2y agoThis type of thing is my biggest AI fear. It’s just too easy to produce bug reports, twitter posts, academic papers, entire books and audiobooks, using AI. While the results are almost entirely trash, we can’t force humans to take the time to categorize and reject them, as there isn’t enough time. The only fix I can think of is going to be to introduce trust models, where you can vouch for people and their outputs, and people can trust their friends, or particular lists. PGP keys aren’t the technical answer (because it’s a mess), but I think something more modern in that area might be needed.
- ronsor 2y agoWith twitter posts, you have it easy because it was 95% trash before AI. You'll definitely have a lot of problem with other content though.
- wang_li 2y agoThere should be consumer protection laws in place that require AI companies to record every result their tools produce. Then when some trash human submits the AI output to a bug tracker, forum, etc. with a negative impact on the victim website, they can submit a claim to the AI company for a $100 million payment due to the inability to prevent the tool from being used improperly.
- lucb1e 2y agoDoes hovering over the reporter's username make the whole page go blank with a generic "An error occurred" for anyone else?
- bagels 2y agoYes.
- Polizeiposaune 2y agoI would assume that this is evidence that the reporting account has been disabled.
- swatcoder 2y agoYes, you can still click through if you don't hover, and the account is gone. Presumably, the code that shows the preview just doesn't handle deleted accounts gracefully.
- Polizeiposaune 2y agoUnfortunate that they deleted it and didn't / couldn't lock the account and flag all its submissions as suspect while leaving them in place for review.
- DanielVZ 2y agoHaving contributed my small grain of sand to the curl project in the past, I can only say I have huge respect for badger. All the issues I worked on he was impressively active on and even though I was a newbie and his language came across a bit terse when making comments, he was never wrong or disrespectful. I can’t imagine how much strain is AI slop putting on curl maintainers so I hope there’s a solution to that in the near future.
- Karellen 2y ago* bagder
- realxrobau 2y agoIt seemed like AI generated stuff from the second sentence 8-(
- Fokamul 2y agoAaaand he's gone.. https://hackerone.com/napol-webug https://hackerone.com/napol-webug New angle of DOS attack? Generate bug reports in hundreds, or thousands and practically DOS maintainers of OSS projects.
- cozzyd 2y agoIn the google cache for that you can find a link to https://webug.xyz/ https://webug.xyz/, which is... something.
- bmacho 2y agoHow do you access google cache? cache:https://hackerone.com/napol-webug Does not work for me. Is there a still working method?
- cozzyd 2y agothe website link appeared in the quoted results when googling napol-webug, at least for me.
- negatendo 2y agodude is creating capital and asset funds for a business that doesn't yet exist. i'm afraid we've got a clinical case of the silicon valley brain worms here folks.
- alkonaut 2y agoIf I found a really valuable exploit that I wanted to avoid seeing fixed for at least a few months, then why now swamp the project with false positives for a period of time so that my exploit, if it's found, is just one of hundreds being reported and IF it's reported, there is a chance it's being drowned or even accidentally removed.
- gus_massa 2y agoPerhaps I'm too optimistic, but the legit exploit will have a very different style. Perhaps broken English and a 50% code and 50% text instead of 10% code and 90% text. I guess that a fast triage to detect non-cookie-cutter reports would be enough (but anoying anyway).
- mmastrac 2y agoI got hit with a CVE spammer last year which forced me to re-release a library to fix a fake vulnerability that cannot be disputed in any way -- https://gist.github.com/6en6ar https://gist.github.com/6en6ar. They do nothing but post exploits where long strings purportedly take a long time to process -- because they are slow to construct! And even more fun, the example exploits often don't even compile. I assumed it was a human, but I'm starting to wonder if this was an early CVE-farming AI bot. The CVE process is very broken and extremely exploitable as a DoS against humans.
- minitech 2y ago> exploits where long strings purportedly take a long time to process -- because they are slow to construct! That’s not an accurate characterization of ReDoS. Even if a long string is required to produce the behavior, the vulnerability is that the string takes a disproportionately long time to process even for its length, such that it becomes disproportionately easy to bring down a service. The CVE scoring system gives denial of service way too much weight if you ask me, but it’s not a fake vulnerability.
- bawolff 2y agoHowever i think there are people spamming fake redos vulns just to get creds. Things like, yeah, if you passed in 10 mb of input this would be a problem, but also some other layer limits it to 100 bytes. ReDos is real in certain circumstances, but it is way way overhyped and usually bullshit.
- mmastrac 2y agoYou missed the point. The code purported to be vulnerable is not slow because of the length of the string. The "example exploit" is slow because the reports use slow methods to construct the string under test. When timing the affected methods, they are _not_ slow.
- minitech 2y agoWell, you didn’t link to that example exploit, and a random sampling from their profile looked legitimate. Do you have the specific link?
- resonious 2y ago> That being said, in cases where the check may be bypassed or in a different implementation scenario, similar vulnerabilities can still appear. This is so funny. "Oh, I see you have a bounds check that prevents vulnerability. BTW, if you remove that bounds check, your code will be vulnerable!!"
- kstrauser 2y agoWe get bug bounty reports like that sometimes. "I think your site might have an XSS vulnerability but your WAF is stopping it." "What I hear you saying is that we don't have an XSS vulnerability." I mean, it's possible we do have a mistake in code somewhere we haven't found yet, but if the system effectively protects it, that's not a vulnerability.
- bean-weevil 2y agoI formerly worked in triage for a bug bounty program. We paid attention to these kinds of reports because it's often possible to bypass the WAF, or at least repurpose the vulnerability in a way the WAF wasn't designed to defend against.
- kstrauser 2y agoAbsolutely! If you have a known SQL injection behind a WAF, you better go fix it! It seems like these reports come down to the equivalent of “I pasted HTML into a form and you displayed the escaped version back to me, but maybe you forgot some tag.” No, I’m not going to turn off our WAF so you can test that hypothesis.
- Retr0id 2y ago> No, I’m not going to turn off our WAF so you can test that hypothesis. It would be worth your while to test it. You could run a dev/testing version of your app on a separate domain, without a WAF, and without any sensitive data held on it. WAFs are a last resort to fix the bugs you didn't know about, and your application should still be safe without a WAF otherwise you're not actually getting the defense-in-depth you wanted. For an attacker that cares enough, WAF bypasses are a near inevitability.
- cozzyd 2y agoI mean, if the reporter actually tried following the PoC they might have realized it's not a valid PoC. (Though to be fair, perror does return a confusing error message in that case). At first I thought they were trying to make the claim that if you lie about size, you can (duh) get a buffer overflow, but they didn't even successfully manage that.
- ivolimmen 2y agoThis is a horrible read...
- leni536 2y agoApart from the LLM bs, it looks like spammers exploit the fact that they can submit bug reports at no to little cost, while the maintainers have to spend a significant amount to triage the reports. If this spamming goes out of control, then I think it will be inevitable that maintainers will need to charge money to triage bug bounty reports to balance this out somewhat. This would obviously suck for all legitimate parties involved.
- Ekaros 2y agoActually this could be an attack in itself. Say you find a significant 0-day in some popular library. And start exploit it, but you at same time bury the reporting system in generated false leads and reports of non-existing issues. Thus taking time away from actual issue while you actively exploit it...
- HL33tibCe7 2y agoThere’s absolutely no excuse for filing utter shit like this. The POC is two lines of Bash, and the author couldn’t be bothered to even run that. https://github.com/webug-lab https://github.com/webug-lab is presumably the author. People who file reports like this should be permanently banned from HackerOne and excised from the security community. They are parasites, leeching off of the time of open-source maintainers. I can’t believe how nice badger is on the thread, frankly. He is well within his rights to be much harsher.
- deleted 2y ago[deleted]
- alkonaut 2y agoThe maintainer vs. AI issue aside: in C when you write a method with a dst pointer and a size_t size argument, is it enough to check the size argument to be sure that the dst pointer will fit the data? It doesn't seem like that would protect against mistakes, for example if I allocate 100 bytes and call the method with 200 for the size_t, then it will pass the check but potentially write out of bounds anyway? I guess what I'm trying to say is: would it not be safer and more ergonomic to use some struct of pointer+size and pass that around just like higher level languages pass around arrays with a known length? That way the invariant that the size of the allocated memory actually matches the size field can be preserved?
- bluGill 2y agoIt is too late to do that. C was built in the 1970's when buffer overflows where only exploited by friends to get a laugh and so they were not security issuses.
- magicalhippo 2y agoThe problem with C isn't that we can't add things to make it safer. It's that we can't remove things to make it safer.
- sourcepluck 2y ago@dang, or whoever has the power to do so: Can the title be changed? It is the exact title of the "report", but it's not a real report, and that's the story here. Keeping the real title of the fake AI-slop-report only adds to the confusion. It's hard to do a neutral, descriptive, non-editorialising, non-clickbait title, but perhaps along the lines of: > Curl maintainers lose time dealing with AI-generated fake security report
- deleted 2y ago[deleted]
- razze 2y agoWe're also seeing symptoms of this in software support. Specifically with flatpak for example, as people start to recommend or wonder about flags (that have never existed) not working. Some even end up writing (abusive) issues about that https://github.com/flatpak/flatpak/issues/6006 https://github.com/flatpak/flatpak/issues/6006
- tdiff 2y agoWould be nice if any of future "C is the root of all evil" articles would refer to this ticket as an example.
- ape4 2y agoI understand this isn't a bug because the length is checked. But it would seem wise to remove uses of strcpy() so automated tools don't complain.