I've a question. This 0-day is a 0-click that didn't require any document download or anything. Simply visiting a http site would do it. What if you have JavaScript disabled be default. Would this exploit still work?
it's http interception so no, I doubt javascript matters at all
0-days exploited by commercial surveillance vendor in Egypt
141–150 of 254 posts
Re: 0-days exploited by commercial surveillance vendor in Egypt
#142I am pretty sure I was hit with this. I had some REALLY weird redirects coming from text msgs. NOT from Egypt. Maybe paranoid. Offline / on new Linux devices for now.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#143It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…
> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?
Re: 0-days exploited by commercial surveillance vendor in Egypt
#144Earlier quoted context omitted.
Poaching founders is an entirely different kettle of fish than just poaching line employees.
Oh, I thought finding these vulns was a highly open-ended endeavor with variable payouts.
100k+ for a Safari on iOS code exec, another 200k for the Safari sandbox escape, then another 500k+ for the kernel exploit?
A full chain is real money. Especially when they resell this ability for 1-2M+ per user.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#145Earlier quoted context omitted.
I feel like you're arguing that these certifications are useless and uncorrelated with security but then you're trying to say that Apple and others are bad for not having them.
Low certification levels certify low levels of security. High certification levels certify high levels of security. EAL4 is known to be too low against modern threats that will attack commercial users. We know this from experience where EAL4 systems are routinely defeated. Higher certification levels, such as the SKPP at EAL6/7, are known to be able to resist against much harder threats such as state actors like the…
I guess I don't know enough to say but I just doubt that, knowing what I know about other certifications. I expect that they're perhaps lightly correlated with security.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#146Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?
Re: 0-days exploited by commercial surveillance vendor in Egypt
#147Though HTTPS is better than nothing, and this attack relies on HTTP to inject the initial payload, state sponsored attackers in some countries can likely just subvert CA or CDN infrastructure instead.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#148Earlier quoted context omitted.
> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?
Likely yes, they were unable to capture the following stages so they don’t know what was exploited after gaining initial execution within the chrome sandbox. Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#149It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…
> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?
Re: 0-days exploited by commercial surveillance vendor in Egypt
#150Earlier quoted context omitted.
Likely yes, they were unable to capture the following stages so they don’t know what was exploited after gaining initial execution within the chrome sandbox. Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.
> Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”. There is certainly many of those that we don't know about, if this was done in Egypt, imagine what a 3 letters agency have
Think of all the insidious corruption we find out about via declassification 50 years later. It's not like human nature has changed.