RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
parsiya.net
parsiya.net
I recall looking into this a while back with the intention of leveraging it for an ancient win32/mfc app. I don’t remember the specifics, but I seem to recall that MS restricted or prevented access to a rather substantial subset of win32.
In this case it's an extension that's not installed by default.
Not whether installing an extension whose purpose is interacting between locally running IDE and locally running VM can be considered opting in it interacting with network in any way.
Yes, indeed!
You can still import all nasty third parties required by marketing department, bypassing first party protections and leading to even worse security. Or maybe maintain allow lists, basically that's a Content Security Policy.
Future is now old man.
On moral/legal issues, integrating script from third or first party hostname sounds like technical detail. If you select partner to run their code on your pages, you should be responsible checking user consent when applicable and taking responsibility. British Airways has been fined £20m even if that script was not on their servers.
One can dream.
Browser are already way too big.
> Do I think there are other security issues here and we can bypass this? Also, yes.
> Do I want to spend more time doing free work for a company with a 2.5 TRILLION market cap? Hell, no.
Troubling.
Either Microsoft or other future vendors can actually honor an established bug bounty program, or the author can sell his findings to the highest bidder. Or the author can simply not spend time and energy finding bugs in the first place.
But does not change the monetary reality
It feels that paired with a good blog (ironically about WLS) this could be very profitable, compared to the $0 MS awarded them.
Bug bounty is good in some respects, but the people who profit the most from it are the companies and platforms. IMO it feels dirty to exploit people’s good intentions and ethics (reporting vs selling) for profits, but that’s corporations for you.
^ this is both a good and a sad indicator, it means the bar of post-exploitation for such a bug (on developers' boxes) is "sufficiently high" that your favorite ransomware gangs are not eager to get on. OTOH it means they have way more "easier" enterprise-y targets...
[0] https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-cod...
Arguably the MIT license gives you more Freedom than the GPL'd Linux kernel or GNU utilities. Trying to draw a distinction between "evil user-unfriendly Microsoft stuff" and "Holy Saviour FOSS" is not meaningful anymore.
[1] https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-cod...
The source code, the editor are. This is like Oracle releasing a proprietary plugin for EMACS and distributing it on Oracle Linux, and someone saying "this is bad, we need FOSS editors!". That wouldn't make EMACS not-FOSS.
(Is it trolling of me to point out that of course the thing people actually want is not the FOSS bit? There are dozens of editors, people want features not ideology)
However...I love Emacs, but as much as I hate to admit it, VSCode's out-of-the-box experience is significantly better than even starter kits like Doom and Spacemacs ):
VSCode is far more "user-friendly" than Emacs or Vim at this point in time. That's definitely something that can be changed, but let's not delude ourselves...
If you find a way to take over MS accounts, or force email swaps, or even gamertag shanaigans, there is too much money to be made, there is not even a point for a bug bounty.
It's like a $40 reward for returning a purse filled with $250k.
I agree with OP: no more free bugs.
I would much rather get $40 dollars for a bug and some public acknowledgement (which I could use to get a better paying job) than to sell it for criminal use.
Taking a US centric view on this is a great way to ensure nation states have compromised your security.
Paying more money isn't going to make someone do the right thing.
Noob question: is there any specific law that punishes describing how to get into a software/electronic system but not actually doing it? Something that is just not purely US-centric.
https://law.stackexchange.com/questions/11552/is-it-illegal-...
Bug bounties need to be higher, because the black market is not the only alternative.
Pay-per-bug-found incentivises plenty of counterproductive things as well, especially if we're talking about people who happily sell to anyone on the black market.
Why would making it easier make it happen less often?
Still bad, but not quite as bad as owning from the browser via localhost GET.
Edit: after reading tfa, it appears: no it can't , but it may due to browser security vulnerabilities.
This is frequently used by apps which are installed on your machine but are accessed by links, such as zoom and discord. I think Zoom removed its server after receiving pressure[0] about it, but discord still does it: Head to https://discord.com/invite/test and it should open your local discord client, or checking the network requests will reveal up to 10 attempted local ports.
[0] https://www.zdnet.com/article/zoom-defends-use-of-local-web-...
Also, strange that this doesn't get a bug bounty payout - it's very severe.
Lovely
The other blockers of course being that I have neither the skills nor the time to find such flaws in the first place!
It is true that there are people out there who do have the skills, and the time, and would be fine with selling their results to third parties, so maintainers (particularly those publishing widely used projects), would do well to treat people who practise safe disclosure with sufficient inducement to keep doing so.
Follow the golden rule.
It's long overdue.