3 ms·
As someone who works with FPGAs/ASICs, this isn't that weird. Everything gets serialized/deserialized these days, so there's all kinds of boundary conditions w
by engtech 14y ago
As someone who works with FPGAs/ASICs, this isn't that weird.
Everything gets serialized/deserialized these days, so there's all kinds of boundary conditions where you can flip just the right bit and get the data to be deserialized the wrong way.
What's more interesting is that it bypasses all of the checks to prevent this from happening.
Here is the wiki page on the INVITE OF DEATH which sounds like the problem you hit:
http://en.wikipedia.org/wiki/INVITE_of_Death http://en.wikipedia.org/wiki/INVITE_of_Death
- engtech 14y agoThe INVITE of death was discovered on Feb 16th, 2009. http://ims-bisf.nexginrc.org/OpenSBC-vul.html http://ims-bisf.nexginrc.org/OpenSBC-vul.html
- deleted 14y ago[deleted]
- huhtenberg 14y ago> Everything gets serialized/deserialized these days, ... and get the data to be deserialized the wrong way. Can you elaborate? I recognize the words, but not the meaning.
- bigiain 14y agoAnybody else waiting for him to reply with something like: "Oh yeah, I used to work at Intel - that nic's got a YAML parser in it"…
- noselasd 14y agoOften there's just a pair of wires/pins into a chip that you use to control the chip, for a NIC, modem, radio, what have you - accompanying this is a protocol you use to comminicate with the chip. For e.g. a NIC, it's not that many things that need to go wrong when you encapsulate a packet it should forward out on the wire so it rather looks like a control packet triggering some undesired results on the chip. Or vice versa.
- mikeash 14y agoINVITE of Death looks completely different. There, malformed packets would cause trouble in the VoIP software that was trying to parse them. Here, well-formed packets would sometimes cause trouble in an ethernet controller that shouldn't even be trying to parse them.
- IheartApplesDix 14y agoWell, it's very weird if you understand anything about Network protocols. It's a layer of complexity that shouldn't be being touched by your NIC, so there shouldn't be a bug there because there shouldn't be code there.
- bigiain 14y ago<hat type="conspiracy theorist">I wonder what _other_ data coming down the wire that nic is monitoring and executing code in response to?</hat>
- IheartApplesDix 14y agoIt's a subset of the misinformation hats, Mr. "HTML coder"
- jacquesm 14y agoIt's the payload that triggers the bug, not a header! Definitely not this bug, the one linked is not intel specific.