Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
f-
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
f-
12y ago
We also have a pretty comprehensive discussion of this and many other vectors in: http://www.chromium.org/Home/chromium-security/client-identi...
62.
▲
by
f-
12y ago
afl-fuzz can be parallelized fairly easily. The exchanged data amounts to newly-discovered, interesting inputs that then seed the subsequent fuzzing work.
63.
▲
by
f-
12y ago
Honestly, I don't think it's been easier in the days of university mainframes. Today, it takes minutes to download, run, and brick new OSes in a VM; you have terabytes of free and easily searchable documentation and code samples a
64.
▲
by
f-
12y ago
Please be very careful when using less popular C/C++ image parsing libraries on anything that is user-controlled or that comes from the Internet. Image, multimedia, and archive parsing are notoriously prone to security bugs. In fact,
65.
▲
by
f-
12y ago
Encoder? You'd probably want to try a decoder as the target binary if you want to make MP3s.
66.
▲
by
f-
12y ago
You can add instrumentation to binaries using DynamoRIO or pin. This isn't currently supported by afl-fuzz out of the box, although there's nothing that makes it fundamentally difficult.
67.
▲
by
f-
12y ago
Sure, it's even called that on the project page :-) It just uses an interesting fitness function that knows nothing about the underlying data format - essentially, "improve the edge coverage in this black-box binary".
68.
▲
by
f-
12y ago
The main problem with SAGE is that at least outside Microsoft, it exists just as a series of (very enthusiastic) papers :-) So, while I suspect it's very cool, it's also a bit of a no-op for everybody else. It's also impossib
69.
▲
by
f-
12y ago
The Linux kernel and the core utilities needed for an user-friendly OS add up to a mind-boggling amount of code, written by thousands of hobbyists over the course of decades. That code base has the benefit of actually existing, being famili
70.
▲
by
f-
12y ago
Yup, unless you are doing something crazy.
71.
▲
by
f-
12y ago
Obviously wasn't a month ago ( https://news.ycombinator.com/item?id=8432826 ), but yeah, it's not exactly fresh.
72.
▲
by
f-
12y ago
Batches of CVE numbers get pre-allocated to major players well ahead of any actual vulns being found, so that there is no need to individually request IDs from a central authority for, say, every single browser bug. That happened here, the
73.
▲
by
f-
12y ago
This is an... odd submission. But I'm the guy who found this and the '78 one. To cut to the chase, run this command from within bash: _x='() { echo vulnerable; }' bash -c '_x 2>/dev/null || echo not vul
74.
▲
by
f-
12y ago
I think there are quite a few people who do make a living by participating in vulnerability reward programs (well, not at $50 level, obviously). Now, I have not seen too many people who would be doing it consistently for many years - simply
75.
▲
by
f-
12y ago
If you followed some common-sense advice [1], you only needed two patches: the original one as a stop-gap measure for the original RCE on September 24, and Florian's prefix-adding patch that came out shortly thereafter (but has taken s
76.
▲
by
f-
12y ago
You essentially can't evaluate that in isolation (looking at their past interactions with the infosec community may help). It gets better: you can't even depend on the large players generally getting it right. If a large organizat
77.
▲
by
f-
12y ago
They applied the unofficial one. The official one uses a different suffix.
78.
▲
by
f-
12y ago
Using env may be slightly more portable if you're using an exotic login shell that doesn't support the "FOO=1 program" syntax - say, tcsh. But for most part, it's probably just people copying-and-pasting stuff witho
79.
▲
by
f-
12y ago
Yup, as of yesterday, they are shipping the unofficial patch. I added a simple command to test if you're patched at the bottom of the blog post.
80.
▲
by
f-
12y ago
It should work on top of the original patch with 4.3. Don't omit 025.
81.
▲
by
f-
12y ago
Since the post is relatively non-technical, I'd like to underscore that there are substantial concerns with the original and the followup patch, because with or without it, the underlying bash code parser is still exposed to the Intern
82.
▲
by
f-
12y ago
There is an unofficial patch that takes a much more reasonable approach: http://www.openwall.com/lists/oss-security/2014/09/25/13
83.
▲
by
f-
12y ago
I helped draft the original blog post :-) To clarify a bit more and help folks evaluate their individual risk, it's worth noting that the impact is limited to a fairly specific scenario. In essence, you needed to have a non-native docu
84.
▲
by
f-
12y ago
Similarly to CSP, onload and onerror are not the only ways to pull it off. The effect of successfully or unsuccessfully loading images or scripts can be usually inferred without that; for example, images have dimensions that, even if you ta
85.
▲
by
f-
12y ago
Such attacks are interesting, but the CSP part is a red herring to some extent; we had this problem without CSP and the issue is mostly that nobody has any good ideas on how to get rid of this class of attacks without breaking the web: htt
86.
▲
by
f-
12y ago
I don't know why they wanted the info (and it was fairly dumb of them to try). Nevertheless, they saw some practical value in it, so did others.
87.
▲
by
f-
12y ago
Well, say... http://www.theregister.co.uk/2010/12/03/browser_history_snif...
88.
▲
by
f-
13y ago
Probably, but in the end, it doesn't matter: there is a single, widely archived mailing list that almost everybody knows about. Outside the several mailing lists we have, there's nothing resembling a central repository of security
89.
▲
by
f-
13y ago
I've been active in the infosec community for ~18 years, probably as one of its more prolific members at times - and similarly to Thomas, I'm not really sure I buy this argument. I don't want to cross-post the entire thing, b
90.
▲
by
f-
13y ago
Well, we have an official reward program with published criteria, and to a large extent, it's just a matter of reputation: if we were unfair or stingy, it would be a very short-sighted strategy. That aside, having another party getting
More ›