Earlier quoted context omitted.
No. RCE is a term of art. It implies arbitrary native code execution.
> It implies arbitrary [ ]native[ ] code execution. This is simply not true in a plurality of cases (eg, it implies that applications running under qemu are incapable of having RCE vulnerabilities) and frankly sounds like a distinction that was made up to avoid admitting that script tags are RCE bugs in web browsers.
Remote Code Execution in Slack desktop apps
181–190 of 201 posts
Re: Remote Code Execution in Slack desktop apps
#182Earlier quoted context omitted.
> It implies arbitrary [ ]native[ ] code execution. This is simply not true in a plurality of cases (eg, it implies that applications running under qemu are incapable of having RCE vulnerabilities) and frankly sounds like a distinction that was made up to avoid admitting that script tags are RCE bugs in web browsers.
It's interesting how much this little subthread recapitulates the experience of responding to the median bug bounty submission.
Re: Remote Code Execution in Slack desktop apps
#183Earlier quoted context omitted.
Don't bug bounties usually have some rules for splitting bounties or else paying only the first reporter in case of multiple independent discovery?
It is typical that only the first reporter gets a bounty; duplicate reports are usually given "duplicate" status. But you might have the same vulnerability found in several different places. Reports should really only be considered duplicates if the fix to one automatically fixes the other also. Your bug found in multiple locations might happen to be set up that way -- or it might not. This exact problem occurs frequ…
Re: Remote Code Execution in Slack desktop apps
#184Earlier quoted context omitted.
I've been in security for a while and once received a report of a CVSS score that was egregiously high at Critical. I modified the assumptions that were made by the reporter and came out with Low. This is one example of why this is a nonsense metric.
Any metric is nonsense if used improperly.
Re: Remote Code Execution in Slack desktop apps
#185Earlier quoted context omitted.
Technically true, but kind of ridiculous. How many people can't get food, but have a computer, electricity, internet connection, a reasonably quiet place to work, deep knowledge of web technology, and enough free time and mental energy to try to build exploits of computer software against an uncertain and distant bug bounty payout? If you're really desperate for food, you should be looking for a salaried position or…
Lots. Many more than you’d expect. To believe otherwise is privilege. It took many years to understand this.
Speaking of privilege, how much privilege is there in believing that ethics aren't important, because you don't know what it's like to live in a place that never even pretended to care about it, and get robbed on a routine basis, because a bunch of other people around you don't care about ethics either, and would rather form a gang and smash anybody who has something they want than work to build a marketable skill?
That is the world you build when you advocate for people not paying attention to the harms of releasing exploits into the wild, because it might pay better than doing the right thing.
Re: Remote Code Execution in Slack desktop apps
#186I wrote that exploit & report. Just some thoughts on comments here. Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming. I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces?…
Just sucks - marketing, legal, the engineer and peers who reviewed it, security..
Re: Remote Code Execution in Slack desktop apps
#187Earlier quoted context omitted.
> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation
> I doubt anybody capable of finding an exploit like this is in that situation Yet the vast amount of hacks or attempts typically originate from China or North Korea...
Re: Remote Code Execution in Slack desktop apps
#188Earlier quoted context omitted.
> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation
I suggest you try and peek outside your bubble then. Software Engineering isn't free money everywhere.
Re: Remote Code Execution in Slack desktop apps
#189Earlier quoted context omitted.
I've met plenty of self-taught hackers in developing countries who were barely employed due to general economic dysfunction. Spend a month or two in Venezuela and you'll find plenty of qualified folks who have no steady job and are scraping by, how do you think people get into crime to begin with?
>> how do you think people get into crime to begin with? lack of opportunity, lack of skills and lack of work ethic. As in it's easy to do, no barrier to entry and always availble. Most crimes don't actually pay very well and have poor return if you've got any sort of marketable skills. Armed robbery of a bank will get you on average $1200 and 15-20 years.
Re: Remote Code Execution in Slack desktop apps
#190Earlier quoted context omitted.
I'm not sure I agree with the parent poster, surely this isn't exactly murder.
It's a hyperbolic cheeky way of pointing out that they're getting off the hook for their first gross transgression. The GP isn't in any way suggesting mishandling this security issue was equivalent to murder. They're pointing out that if the transgression were more severe, we'd easily see right through the hole in the reasoning.