‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. oefrha · · focus · HN ↗
    Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it&#x27;s easier than ever to turn vulnerabilities into full compromises. At some point we&#x27;ll have to replace all parsers with something at least as safe as <a href="https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;wuffs" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;wuffs right? Otherwise ImageMagick and co. will just keep giving.
    1. djxfade · · focus · HN ↗
      PHP still rules the world, even though many doesn&#x27;t want to realize it. It&#x27;s still the biggest web language by a far margin
      1. willy_k · · focus · HN ↗
        Phones don’t “rule the world” of cinematography, despite the majority of videos being from phones. The serious stuff, professional and personal, uses cameras.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.