‹ BackHN Continuity

Thread

Data-only attacks are easier than you think (2024)

102 points · 45 comments · segfaultbuserr

  1. miellaby · · focus · HN ↗
    > Data-only attacks, those that do not affect a program’s control flow, have long been considered too sophisticated and niche to pose a practical threat.

    Leveraging user data to get malicious behavior is the basis of interpreter eval injection (php, js, perl, shell calls, SQL ...). These attacks are like 50 years old. What do I miss?

    1. mtud · · focus · HN ↗
      I think of “data-only” as weird shorthand for “app-specific exploit primitives.”

      An example I’ve seen somewhere is if a buffer overflow lets you change the value of another variable, but not directly control the instruction pointer. The exploit developer then has to figure out a way to turn their very constrained primitive into something useful, versus having access to a more powerful and generic primitive (stack return pointer, write-what-where, etc).

      The example in the post is, basically, command injection, but it requires you to manipulate the app-specific state into a vulnerable state.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.