10 ms·
The Chrome VRP Panel has decided to award $250k for this report
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- krtkush 1y agoHow does one start acquiring skills like these?
- mdaniel 1y agoPractice, and having supernatural perseverance (although probably not in that order) I'd guess the curriculum is half reverse engineering and half reading any write-ups to see the attacks and areas of attack for inspiration
- anthonj 1y agoI get the feeling these kind of skills are very rare because they fall in the category "understanding and debugging other people code/mess", while most people prefer to build new things (and often struggle to debug their own work). It takes a lot a passion and dedication to security and reverse engineering to get there.
- WalterBright 1y agoSpending a lot of time debugging code. Eventually, the pattern recognizer in your brain will pick out the bugs. The term for this is "code smell". For example, when I'd review C code I'd look at the str???() function use. They are nearly always infested with bugs, usually either neglecting to add a terminator zero or neglecting to add sufficient storage for the terminating zero.
- jve 1y agoIt is crazy that anytime someone works on application layer and wants to manipulate string, which is a very, very common thing to do when writing application, one has to consider \0 which would be an implementation detail. How can that language still be so popular?
- avar 1y agoBecause whatever language you think should be popular instead is running on a mountain of C code, but the reverse isn't true.
- WalterBright 1y agoThe D implementation and runtime library has zero C code in it.
- avar 1y agoAnd when you run that compiler implementation, what language family was used to implement the OS and kernel it's running on, the firmware you're using etc? That's what I meant, not that self hosted compliers don't exist.
- AlienRobot 1y agoOkay, I want to make a desktop app that runs on Linux. Which language should I use? Java?
- rkomorn 1y agoSome current trendy options would be Kotlin (with Kotlin Multiplatform) or C# (with Avalonia UI). Edit: I guess I should've at least asked myself if the question was rhetorical.
- uecker 1y agoWhatever you do, please do not use a language that makes it difficult to provide security updates: https://www.debian.org/releases/trixie/release-notes/issues.html#limitations-in-security-support https://www.debian.org/releases/trixie/release-notes/issues....
- Hilift 1y agoRead the blogs of the guys creating the bugs.
- baobabKoodaa 1y ago[flagged]
- saagarjha 1y agohttps://pwn.college/ https://pwn.college/
- tptacek 1y agoBy reading and keeping up with the published work in browser exploit development, replicating it yourself, and then finding you have a knack for spotting vulnerabilities in C++ code.
- ad-astra 1y agoImpressive. Feel like finding issues like this in such a large project is like looking for a needle in a haystack
- georgemcbay 1y agoFinding issues in large complex projects is generally easier than smaller projects. More code, more bugs. But its still difficult to find serious issues on the level of a sandbox escape in Chromium just because Google's long-running reward system means lots of people have spent lots of time looking into it, both manually and using automated fuzzer tools. Back in ye olden days of 2014 I randomly stumbled upon a Chrome issue (wasn't trying to find bugs, was just writing some JavaScript code and noticed a problem) and reported it to Google and they paid me $1,500. Not bad for like half an hour's work to report the issue. https://issues.chromium.org/issues/40078754 https://issues.chromium.org/issues/40078754
- sour-taste 1y agoI feel like it's the opposite. In a huge project there's bound to be many weird interactions between components, and it's about picking the important/security relevant ones and finding edge cases. In this case the focus was on the interaction between the renderer process and the broker. That forms a security boundary so it makes sense to focus your efforts there - google will pay for such exploits since they can in theory, when combined with other exploits in the renderer process, lead directly to exploits that can be triggered just by opening a web page. So, yes, chrome is a huge project but the list of security-relevant locations to probe actually isn't actually all that long. That's not to diminish the researchers work, it still takes an insane amount of skill to find these issues.
- hnlmorg 1y agoFinding a problem that deserves a bug bounty reward is a very different beast to just finding quirks. I read from one security researchers somewhere that professionals wouldn’t find enough bug bounty worthy problems in high enough frequency to pay their bills. So they’ll sometimes treat things like this more as a supplement to promote their CV rather than as a job itself.
- high_na_euv 1y agoKind of life changing money, good to see such rewards
- socalgal2 1y agothe first time I got a bonus that big, $240k, I thought it would be life changing. the gov took $100k in taxes. I paid off my car $20k. then when I really thought about it there wasn’t much I could do. It was not a down payment on a house in LA/SF/NYC. it was not enough to start a company and hire people. If I’d changed my life style to be like a college student and live with roommates then it might have given me 2-3 years of student lifestyle but I was 34 and not prepared to go back to student lifestyle To be honest it was super disappointing. Of course getting a $240k bonus is a privilege. My only point was it didn’t change my life like I thought it would. And, that was 25 years ago. today, even a million ($600k after taxes) in those 3 cities won’t likely change your life. Maybe you could put a down payment on a house or pay for your kids college tho but it not the freedom I thought it would be
- jama211 1y agoFor you maybe. For someone in debt or who has never ever had a financial safety net, the amount of stress relief from finally having a bit of safety money behind you is mental.
- gambiting 1y agoDepends where you live. Where I'm from $240k would buy you a really nice house with lots of land, and you'd have money left over. >>won’t likely change your life. Maybe you could put a down payment on a house or pay for your kids college tho but it not the freedom I thought it would be How is being able to put a down paymenent on a house or being able to send your kids to collage debt-free not life changing?
- sgjohnson 1y ago> How is being able to put a down paymenent on a house or being able to send your kids to collage debt-free not life changing? Because neither of those are going to change your daily life that much? It simplifies a thing or two, but neither of those things are life-changing.
- MrGilbert 1y ago"Decent." was the first word that came into my mind. After a second, I realized that 250,000 USD ist basically 0.00022 % of Alphabet's (Google's?) annual net income [0]. A life changing amount of money for an individual, but nothing more than a small blip on Google's charts. Of course, I'm aware of "budgets" and "departments", and that one simply does not move funds between departments. And while my mind is on the verge of "maybe they should have paid more?", the numbers would mean that even 10x the sum would move the percentage by one decimal. It's wild how much money big corporations have. I highly applaud the researcher for their tremendous amount of skill and dedication. [0] https://www.reddit.com/r/google/comments/1lh0pl4/google_is_now_the_most_profitable_company_in_the/ https://www.reddit.com/r/google/comments/1lh0pl4/google_is_n...
- brabel 1y agoHow much Alphabet makes is almost irrelevant. The incentive here should be for security researchers. As long as there's enough incentive for security researchers to continue to report the bugs they find (which must be balanced against the potential payment a criminal could get if exploiting the bug, which is not directly correlated to the company's income either, at least not necessarily), the payment is appropriate.
- NitpickLawyer 1y agoTo be fair, goog has to pay comparable to other 3rd party brokers, and not necessarily "potential payment by exploiting the bug". Finding an exploit and being able to deploy it for financial gains are two distinct problems, with separate skillsets, risks, etc. Plus there are some other benefits of disclosing to goog. After you get into VRP you get access to grants & stuff and can basically ask to study a problem and get funded for that effort. Being able to blog about it, pad your experience, etc etc. All while not having to look over your shoulder for 3 letter agencies your whole life :)
- sneak 1y agoYou think state intelligence agencies don’t hack whitehats for their 0days? You know there’s ongoing and plausible efforts by at least 3 organizations to conquer the Earth, right?
- brohee 1y agoHe had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...
- whatever1 1y agoWhy not collect from both of the sources? First collect with your black hat and then with your white.
- londons_explore 1y agoTypically can't do that. Security services tend to anonymously report security flaws they use after use against any high value target, since they don't want the opponent using those same flaws back at them.
- whatever1 1y agoPrivate sector has the incentive of keeping an exploit open for as long as possible. Several cases with iPhone exploits that were apparently open (and sold) for years.
- ajb 1y ago"If I report the body, no-one will suspect I'm the murderer" Yes they will.
- johnisgood 1y agoWhich is why people are hesitant to report a body they have not killed, just found!
- deleted 1y ago[deleted]
- helsinkiandrew 1y agoLink to the reward comment: https://issues.chromium.org/issues/412578726#comment26 https://issues.chromium.org/issues/412578726#comment26
- strstr 1y ago“ Default disclosure for this issue is 11 August. Opening this issue just five days early for visibility this particular week. :)” Hello Defcon!
- deleted 1y ago[deleted]
- lightdev0405 1y ago[dead]
- colbyn 1y agoSuppose someone wanted to dive into other projects with the ambition of finding high value bugs. Besides chromium what would you recommend or consider? What would be your thought process for deciding what projects to look into?
- kafrofrite 1y agoThe answer to your question is WebKit (because iOS), kernels (XNU, Linux, Windows) etc. In case you are not familiar with the domain I'd start with user-space exploitation and relevant write ups to get my feet wet. You'll find plenty of write ups, blogs etc. so I'll skip those. Some of the books I generally found interesting are [1],[2], [3]. There's more to that, including fundamental concepts of CS (e.g., compilers and optimization in JITs, OS architecture etc.). I believe also https://p.ost2.fyi/dashboard https://p.ost2.fyi/dashboard has some relevant training. [1] https://nostarch.com/zero-day https://nostarch.com/zero-day [2] https://nostarch.com/hacking2.htm https://nostarch.com/hacking2.htm [3] https://ia801309.us.archive.org/26/items/Wiley.The.Shellcoders.Handbook.2nd.Edition.Aug.2007/Wiley.The.Shellcoders.Handbook.2nd.Edition.Aug.2007.pdf https://ia801309.us.archive.org/26/items/Wiley.The.Shellcode...
- dontdoxxme 1y agoBugs are "High value" in different ways, you have to find the companies willing to pay highly. Most of the high payers are on bug bounty programs (like hackerone.com) and don't always give you ability to talk about bugs later. Google is quite unique here, particularly given Chrome is paying easily 10x what Mozilla would for a sandbox escape. Apple is in the middle -- per [1] a "WebContent sandbox escape" would be $50k, but to get $250k on their scale you need to combine that with a kernel bug. So if you want to optimise for "value", you have to pick the targets that are easier (still not easy, obviously). [1]: https://security.apple.com/bounty/categories/ https://security.apple.com/bounty/categories/
- deleted 1y ago[deleted]
- OutOfHere 1y agoIt is unfortunate that there is no web browser in a memory safe language. As I understand, both Chromium and Firefox use C++, although Firefox partly uses Rust. This has put billions of people at risk.
- qcnguy 1y agoThis bug is a logic error iiuc so language wouldn't help.
- acer4666 1y agoThis post is about a logic bug that could have happened in any language
- camdroidw 1y agoServo project is active and probably usable in a year or two (but as others have said this bug is different)
- PhilipRoman 1y agoOne of the biggest security holes is the JIT engine, rewriting it in Rust or any other language wouldn't make a difference, since it is effectively an inner platform.
- dig1 1y agoSandbox escape with high-quality report in Chrome: $250k [1], yet Mozilla will offer you $20k [2] for that... [1] https://bughunters.google.com/about/rules/chrome-friends/5745167867576320/chrome-vulnerability-reward-program-rules#memory-corruption-vulnerabilities https://bughunters.google.com/about/rules/chrome-friends/574... [2] https://www.mozilla.org/en-US/security/client-bug-bounty/ https://www.mozilla.org/en-US/security/client-bug-bounty/
- mosselman 1y agoHave you looked at the financial health of the one company vs the other? I am pretty sure Google is making more than 10x the money Mozilla is making.
- MrGilbert 1y agoAccording to Wikipedia, that's 0.012% of their net income. [0] While I'm being told in the comments that this is not the way to look at it, it means that this is, percentage wise, 50x the amount that Google is paying. Sounds fine to me. [0]: https://en.wikipedia.org/wiki/Mozilla_Corporation https://en.wikipedia.org/wiki/Mozilla_Corporation //Edit: Had a typo in my percentage. 20.000 of 157.000.000 is, indeed, 0.012% - that makes it 50x the amount of Google's percentage.
- FirmwareBurner 1y ago>According to Wikipedia, that's 0.0012% of their net income. How much of the Mozilla foundation's income goes into product development nowadays?
- matsemann 1y agoIs there somewhere explaining this bug in terms understandable for someone not dabbling in this? I don't really understand how this works to "escape the sandbox". Normally it's like a website you visit that get access it shouldn't have. But this talk about renderers and native apis make it seem like it's stuff another process on the computer would do?
- deleted 1y ago[deleted]
- Retr0id 1y agoFirst you compromise the renderer process via e.g. a bug in the JS engine. But even if you have native code execution in the context of the renderer process, you're still in a sandbox. The bug in the OP is for the second stage - breaking out of the sandbox. The referenced `patch.diff` is basically for simulating a compromised renderer.
- matsemann 1y agoAh, so it's like a two stage rocket, this turns a small exploit into a humongous one?
- baobabKoodaa 1y agoThis sounds like a good way to think about exploit chains (though I'm not an expert)
- tetha 1y agoOr an escape room, indeed. Once you're thinking along the lines of "Alright, if I had some order of flags, I could solve that thing over there. If I knew some kind of weights, I could solve that over there. And if I could find a light bulb I could deal with that over there", you're kinda in the mindset of finding an exploitation chain. It's just that in the security world, it's more about bad memory accesses, confusing programs into doing the right actions with wrong files, file permissions being weird and such.
- 1y ago
- mkagenius 1y agoImpressive speed on rewarding as well. Around 4 weeks. Lot of companies will sit for months just to acknowledge your submission.
- deleted 1y ago[deleted]
- BillLumbergh 1y agoGoogle have money to burn though.
- AJRF 1y agoI wonder how much the black market would pay for an exploit like that - anyone know?
- defraudbah 1y agonot 250k for sure :) Google security team is really good, however sometimes things are controversial because certain bugs gets ignored in MS-way which is famous for not paying/not fixing.
- tptacek 1y agoGrey market, not black. It's been several months since I've talked to anyone in the space but full-chain reliable quiet Chrome exploit packages were high six figures, with discussions starting about bugs reaching 7 figures imminently, and the people I talked to might have been talking that down (or talking it up). Again, remember that grey market payouts are tranched, so you could get 3x more than Google would pay, or you could get 0.5x, and for much more work.
- ertucetin 1y agoDoes this mean engineers of Google can't fix it?
- saagarjha 1y agoNo, it was fixed after it was reported.
- austin-cheney 1y agoI didn’t get anything for my JavaScript recursive reference failure defect report a decade ago, but then it also wasn’t a sev1 security compromise defect either.
- geertj 1y agoOf note, this is a logic/timing bug, and Rust would not have prevented this.
- Avamander 1y agoAlthough seeing these bugs fixed and getting rewarded for finding them is great, I still think that Microsoft's idea of virtualising the entire browser process was genius. It also feels better than any "lockdown"-like mode that maybe just disables some JIT engine or two. I'd really like that on both Linux and macOS.
- brcmthrowaway 1y agoAre there people who work full time from income on bug bounties?
- landr0id 1y agoYes. There are plenty of folks who submit to the company I work for who live in regions of the world that are extremely low cost of living/salary (in USD terms) and most BB programs pay out fixed USD rates. It can be very lucrative.
- tptacek 1y agoTo add to the sibling comment, there are also many different ways of making a living doing this stuff: * You can find killer clientside bugs where the bounty will cover a year's worth of compensation (bear in mind you'll get maybe 1.5 of these payouts a year on your own if you're good but replacement-level) * You can find these kinds of bugs and work with brokers to sell them to grey-market buyers along with enablement/implants --- more development work, a little more market risk. * You can find smaller, easier bugs (serverside, web bugs) that get nothing resembling these kinds of payouts but are much easier to find, and make good money on volume. This is a much more common way of making a living on bounty payments.
- brcmthrowaway 1y agoThis seems harder and riskier than a full time wage - almost like a salesman who makes money from commission.
- tptacek 1y agoThe salesperson earning much of their annual take-home from variable compensation is one of the most common white collar jobs there is.
- tantalor 1y agoI'm highly skeptical this level of bug bounty would be sustainable by whatever company ends up buying Chrome after DOJ forces it to be divested.
- ariel4cjtf 1y agoDescargas virus