‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. oefrha · · focus · HN ↗
    Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it&#x27;s easier than ever to turn vulnerabilities into full compromises. At some point we&#x27;ll have to replace all parsers with something at least as safe as <a href="https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;wuffs" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;wuffs right? Otherwise ImageMagick and co. will just keep giving.
    1. walrus01 · · focus · HN ↗
      It does make me wonder how much this could be hardened by, to put it in an extremely crude way, taking the current imagemagick code base and throwing a bunch of adversarial SOTA LLMs at it to discover &#x27;bugs&#x27; and exploits of this nature until it can be coaxed into a less dangerous state. Or even using the LLMs to fully port its functionality to a memory safe language. Would take a while to get all the changes approved and then into various distribution imagemagick packages.
      1. sweetjuly · · focus · HN ↗
        I suspect the latter is much easier and cheaper than the former? You can port a lot of software with cheap (or even local) models if you&#x27;re tenacious whereas finding all the bugs is both very very expensive (if it&#x27;s even possible) and potentially never ending (there&#x27;s always new code and bugs!).
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.