Live data from Hacker News

Remote Code Execution in Slack desktop apps

hackerone.com

181–190 of 201 posts

Re: Remote Code Execution in Slack desktop apps

#181

Earlier quoted context omitted.

No. RCE is a term of art. It implies arbitrary native code execution.

> It implies arbitrary [ ]native[ ] code execution. This is simply not true in a plurality of cases (eg, it implies that applications running under qemu are incapable of having RCE vulnerabilities) and frankly sounds like a distinction that was made up to avoid admitting that script tags are RCE bugs in web browsers.

It's interesting how much this little subthread recapitulates the experience of responding to the median bug bounty submission.

Re: Remote Code Execution in Slack desktop apps

#182

Earlier quoted context omitted.

> It implies arbitrary [ ]native[ ] code execution. This is simply not true in a plurality of cases (eg, it implies that applications running under qemu are incapable of having RCE vulnerabilities) and frankly sounds like a distinction that was made up to avoid admitting that script tags are RCE bugs in web browsers.

It's interesting how much this little subthread recapitulates the experience of responding to the median bug bounty submission.

Well, modulo "responding to a submission" versus "reporting a vulnerabity", we can certainly agree on that at least.

Re: Remote Code Execution in Slack desktop apps

#183
post #31

Earlier quoted context omitted.

Don't bug bounties usually have some rules for splitting bounties or else paying only the first reporter in case of multiple independent discovery?

It is typical that only the first reporter gets a bounty; duplicate reports are usually given "duplicate" status. But you might have the same vulnerability found in several different places. Reports should really only be considered duplicates if the fix to one automatically fixes the other also. Your bug found in multiple locations might happen to be set up that way -- or it might not. This exact problem occurs frequ…

(You could achieve exactly what laurent92 is asking for by taking an issue type ("SSRF") out of scope for a period.)

Re: Remote Code Execution in Slack desktop apps

#184
post #162

Earlier quoted context omitted.

I've been in security for a while and once received a report of a CVSS score that was egregiously high at Critical. I modified the assumptions that were made by the reporter and came out with Low. This is one example of why this is a nonsense metric.

Any metric is nonsense if used improperly.

Any ouija board lies with the wrong seance supervisor

Re: Remote Code Execution in Slack desktop apps

#185
post #130

Earlier quoted context omitted.

Technically true, but kind of ridiculous. How many people can't get food, but have a computer, electricity, internet connection, a reasonably quiet place to work, deep knowledge of web technology, and enough free time and mental energy to try to build exploits of computer software against an uncertain and distant bug bounty payout? If you're really desperate for food, you should be looking for a salaried position or…

Lots. Many more than you’d expect. To believe otherwise is privilege. It took many years to understand this.

Dude, if somebody out there somewhere is seriously doing that, they really need some education in effective careers to pursue. That's a lot more likely to improve their lives than complaints about the social effects of the size of bug bounty payouts.

Speaking of privilege, how much privilege is there in believing that ethics aren't important, because you don't know what it's like to live in a place that never even pretended to care about it, and get robbed on a routine basis, because a bunch of other people around you don't care about ethics either, and would rather form a gang and smash anybody who has something they want than work to build a marketable skill?

That is the world you build when you advocate for people not paying attention to the harms of releasing exploits into the wild, because it might pay better than doing the right thing.

Re: Remote Code Execution in Slack desktop apps

#186
post #39

I wrote that exploit & report. Just some thoughts on comments here. Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming. I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces?…

I'm so sorry this happened, the CSO reached out and acknowledged the issue which was.. The minimum, but I'd be doing an internal RCA at Slack for how that post made it public without any acknowledgement.

Just sucks - marketing, legal, the engineer and peers who reviewed it, security..

Re: Remote Code Execution in Slack desktop apps

#187
post #79

Earlier quoted context omitted.

> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation

> I doubt anybody capable of finding an exploit like this is in that situation Yet the vast amount of hacks or attempts typically originate from China or North Korea...

And? If they’re hacking for the DPRK they’re probably in the 1% most privileged of the country, they’re definitely not going to be the ones starving.

Re: Remote Code Execution in Slack desktop apps

#188
post #94
post #79

Earlier quoted context omitted.

> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation

I suggest you try and peek outside your bubble then. Software Engineering isn't free money everywhere.

You seem to be arguing against a straw man. Nobody said software engineering is free money, I said that a software engineer with the knowledge, skills and tools necessary to find an exploit like this is definitely not starving. In pretty much every country in the world, someone with those skills will be better off than 90% of the population

Re: Remote Code Execution in Slack desktop apps

#189

Earlier quoted context omitted.

I've met plenty of self-taught hackers in developing countries who were barely employed due to general economic dysfunction. Spend a month or two in Venezuela and you'll find plenty of qualified folks who have no steady job and are scraping by, how do you think people get into crime to begin with?

>> how do you think people get into crime to begin with? lack of opportunity, lack of skills and lack of work ethic. As in it's easy to do, no barrier to entry and always availble. Most crimes don't actually pay very well and have poor return if you've got any sort of marketable skills. Armed robbery of a bank will get you on average $1200 and 15-20 years.

I would add poor impulse control

Re: Remote Code Execution in Slack desktop apps

#190
post #30

Earlier quoted context omitted.

I'm not sure I agree with the parent poster, surely this isn't exactly murder.

It's a hyperbolic cheeky way of pointing out that they're getting off the hook for their first gross transgression. The GP isn't in any way suggesting mishandling this security issue was equivalent to murder. They're pointing out that if the transgression were more severe, we'd easily see right through the hole in the reasoning.

In its hyperbolic cheek, it overlooks the fact that we can overlook a first offense, precisely because it’s not a matter of life and death.
Post reply on HN