Earlier quoted context omitted.
You don't think there is a place for giving vendors time to fix the exploit before handing it over to everyone who can use it maliciously?
Not at the cost of leaving end users vulnerable and in the dark, vendors can deal with the consequences of their choices. Hard lessons are needed, having attempted to disclose serious vulnerabilities in T-Mobile USA's APIs by reaching out repeatedly, most vendors will not patch in an urgent manner, and some (like T-Mobile) are content to leak customer info indefinitely. It is a culture problem, and it will take (fina…
VirtualBox E1000 Guest-to-Host Escape
71–80 of 118 posts
Re: VirtualBox E1000 Guest-to-Host Escape
#72Re: VirtualBox E1000 Guest-to-Host Escape
#73This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
Re: VirtualBox E1000 Guest-to-Host Escape
#74FTA : >>> a browser opened a malicious website in the guest OS is exploited, a browser sandbox escape is made to gain full ring 3 access, an operating system vulnerability is exploited to pave a way to ring 0 from where there are anything you need to attack a hypervisor from the guest OS. I cracked several games in the end of the 80's but that was nowhere as hard as this seems to be. How do researchers find the time…
The rest is just to show a scenario where this is actually a problem.
Re: VirtualBox E1000 Guest-to-Host Escape
#75This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
https://arstechnica.com/information-technology/2015/08/oracl...
This kind of attitude goes all the way back to 2002 https://www.theregister.co.uk/2002/01/16/oracle_security_cla...
Re: VirtualBox E1000 Guest-to-Host Escape
#76I think the author brings up a good point about so-called "responsible disclosure" (a self-serving term by the vendors). I'm paraphrasing his 3 reasons for disclosing immediately: 1. It's unacceptable to wait half a year until a vulnerability is patched. 2. Bug bounties are riddled with tricks to delay you, shenanigans as to whether they'll pay you or not, and games to low ball the price. 3. It's arrogant to wait mon…
Re: VirtualBox E1000 Guest-to-Host Escape
#77Earlier quoted context omitted.
There are plenty of other big companies behaving similarly. HP comes to my mind also, but I cannot find the statistics which quantified worst maintainance practices.
Other companies may be behaving similarly, but Oracle is the perceived worst, and it says something. Because, they plainly don't hide it and try to be nice, at least. I also think that they're the worst in the industry.
Re: VirtualBox E1000 Guest-to-Host Escape
#78Re: VirtualBox E1000 Guest-to-Host Escape
#79Earlier quoted context omitted.
The author here just blindly assumes a lot of things about VirtualBox's bug bounty program. Many, like Google, put a very strict limit, and they will release the details when that time is over. I think it's more respectful to at least give them a chance, rather than throwing a hot shit on their lap and making hundreds of people's life a living hell for a week. The engineers in charge quickly patching this up aren't t…
Blindly assuming? https://blogs.securiteam.com/index.php/archives/3736 Sounds pretty first hand to me.
> While the crashing bug was reported to the VirtualBox tracker (https://www.virtualbox.org/ticket/16444), it was never considered a security vulnerability, and is not marked as one. This ticket is 15 months old at the time of writing this post and still marked as unresolved.
Re: VirtualBox E1000 Guest-to-Host Escape
#80This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
> While the crashing bug was reported to the VirtualBox tracker (https://www.virtualbox.org/ticket/16444), it was never considered a security vulnerability, and is not marked as one. This ticket is 15 months old at the time of writing this post and still marked as unresolved.
They might not be The Worst, but at 15 months, they're not great.