Live data from Hacker News

VirtualBox E1000 Guest-to-Host Escape

github.com

71–80 of 118 posts

Re: VirtualBox E1000 Guest-to-Host Escape

#71
post #23

Earlier quoted context omitted.

You don't think there is a place for giving vendors time to fix the exploit before handing it over to everyone who can use it maliciously?

Not at the cost of leaving end users vulnerable and in the dark, vendors can deal with the consequences of their choices. Hard lessons are needed, having attempted to disclose serious vulnerabilities in T-Mobile USA's APIs by reaching out repeatedly, most vendors will not patch in an urgent manner, and some (like T-Mobile) are content to leak customer info indefinitely. It is a culture problem, and it will take (fina…

So... It's okay to harm third parties, i. e. VirtualBox users, not just as an unfortunate but unavoidable side effect, but as your means to punish the vendor for their (neglient? wilful? morally depraved?) failure to follow the idealised processes you envision, and for not honouring your genius with whatever your ego believes it is owed?

Re: VirtualBox E1000 Guest-to-Host Escape

#72
The number 3. oh my. It's ridiculous what people do with the bugs their found since Heartbleed. I don't remember anything like that before, but ever since every security issue needs a logo and a catchphrase for some reason.

Re: VirtualBox E1000 Guest-to-Host Escape

#73

This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…

Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?

"You need to think of Larry Ellison the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower hates me' -- lawnmower doesn't give a shit about you, lawnmower can't hate you. Don't anthropomorphize the lawnmower. Don't fall into that trap about Oracle."

Re: VirtualBox E1000 Guest-to-Host Escape

#74
post #52

FTA : >>> a browser opened a malicious website in the guest OS is exploited, a browser sandbox escape is made to gain full ring 3 access, an operating system vulnerability is exploited to pave a way to ring 0 from where there are anything you need to attack a hypervisor from the guest OS. I cracked several games in the end of the 80's but that was nowhere as hard as this seems to be. How do researchers find the time…

Of course they started with exploiting the emulated device using a VM where they have full control.

The rest is just to show a scenario where this is actually a problem.

Re: VirtualBox E1000 Guest-to-Host Escape

#75

This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…

Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?

Oracle are actively hostile to the security researcher community, with their CISO having told customers and researchers off for attempting to find issues in their products

https://arstechnica.com/information-technology/2015/08/oracl...

This kind of attitude goes all the way back to 2002 https://www.theregister.co.uk/2002/01/16/oracle_security_cla...

Re: VirtualBox E1000 Guest-to-Host Escape

#76

I think the author brings up a good point about so-called "responsible disclosure" (a self-serving term by the vendors). I'm paraphrasing his 3 reasons for disclosing immediately: 1. It's unacceptable to wait half a year until a vulnerability is patched. 2. Bug bounties are riddled with tricks to delay you, shenanigans as to whether they'll pay you or not, and games to low ball the price. 3. It's arrogant to wait mon…

In this case there is an easy mitigation for people aware of the vulnerability (change virtual network adapter), and of course they have to run a malicious guest to start with. I'm not sure this argument holds up as well if this were an RCE in an unauthenticated network service that can't be mitigated.

Re: VirtualBox E1000 Guest-to-Host Escape

#77
post #62

Earlier quoted context omitted.

There are plenty of other big companies behaving similarly. HP comes to my mind also, but I cannot find the statistics which quantified worst maintainance practices.

Other companies may be behaving similarly, but Oracle is the perceived worst, and it says something. Because, they plainly don't hide it and try to be nice, at least. I also think that they're the worst in the industry.

One of my uncles moved to another state and was telling me all about how Oracle pays a lot there and I should move there. I told him I absolutely never would. He just wouldn't understand it, and kept nudging so I told him my wife would not want me to move to another state, thankfully that settled that.

Re: VirtualBox E1000 Guest-to-Host Escape

#78
Given the prevalence of security flaws and the seriousness of the consequences of a breach, I'm still surprised why people are so quick to dismiss high security systems like OpenBSD. Just a couple of days ago someone was incredulous that I would consider vmm from OpenBSD for virtual machines, but I'd rather have a secure, open source virtual machine, than a bug infested virtual machine from Oracle. But it is hard to argue with someone who has made a billion dollars from bug infested software... I guess it is really a balance between having cool new features people will buy and good-enough security for your purpose (or good enough for your customers purposes anyways). Maybe I should go work for Visa, they probably care about security.

Re: VirtualBox E1000 Guest-to-Host Escape

#79

Earlier quoted context omitted.

The author here just blindly assumes a lot of things about VirtualBox's bug bounty program. Many, like Google, put a very strict limit, and they will release the details when that time is over. I think it's more respectful to at least give them a chance, rather than throwing a hot shit on their lap and making hundreds of people's life a living hell for a week. The engineers in charge quickly patching this up aren't t…

Blindly assuming? https://blogs.securiteam.com/index.php/archives/3736 Sounds pretty first hand to me.

Specifically:

> While the crashing bug was reported to the VirtualBox tracker (https://www.virtualbox.org/ticket/16444), it was never considered a security vulnerability, and is not marked as one. This ticket is 15 months old at the time of writing this post and still marked as unresolved.

Re: VirtualBox E1000 Guest-to-Host Escape

#80

This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…

Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?

From GP's link:

> While the crashing bug was reported to the VirtualBox tracker (https://www.virtualbox.org/ticket/16444), it was never considered a security vulnerability, and is not marked as one. This ticket is 15 months old at the time of writing this post and still marked as unresolved.

They might not be The Worst, but at 15 months, they're not great.

Post reply on HN