Another example for why system() is so dangerous to use. I also don't understand why it needs to show the dialog in dom0. If you have the option to handle attacker controlled input on the unprivileged side, you should do that instead of putting a lot of logic on the privileged side.
> why it needs to show the dialog in dom0 I think it's the "secure screen" that cannot be manipulated by the malware in a VM. I'd expect a password entry dialog to also be handled like that.
Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
31–40 of 104 posts
Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
#32Reminds me of Theo DeRaadt again: https://marc.info/?l=openbsd-misc&m=119318909016582
[flagged]
Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
#33Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
#34Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
#35Earlier quoted context omitted.
All I see is rudeness, insults, and arrogance sparkled with inklings of technical arguments. Worthless.
But, and this is the important part, is he wrong?
Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
#36Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
#37Wow, this is serious. Makes you think, that even though QubesOS attack surface is so tiny (well-designed to be secure) there are still vulnerabilities to be found. Worth noting that (as I understand) this vulnerability occurs only when doing copy-to-VM from Dom0: >Note that the VM variant of `qvm-copy-to-vm` is not affected, as its version of the error reporting function does not use `system()`: Since you should not…
Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
#38Reminds me of Theo DeRaadt again: https://marc.info/?l=openbsd-misc&m=119318909016582
I feel that, in fairness, one should at least read Adam’s response, though ideally all subsequent mails: https://marc.info/?l=openbsd-misc&m=119320496730314&w=2 Theos is a very opinionated and not necessarily wrong position, but I feel also a bit too reductive given we are eternally having to deal with compromises of some form. Also, lest we forget, it has been two decades in the interim and oh so much has changed. I…
Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
#39Earlier quoted context omitted.
[flagged]
It has? News to me. Go on any major thread on this page, you’ll witness similarly strong pushback visa-vi buying into corporate backed hype, akin to the overconfidence in virt security he pointed at back then.