How to get a heart attack while using JEB decompiler (2022)
blog.stmcyber.com
blog.stmcyber.com
In general the state of reverse engineering tool security seems pretty bad. Common tools like binutils (objdump, readelf, gdb, etc.), IDA, and even Wireshark have had memory corruption bugs. For example, it's pretty easy to get Wireshark to crash on a NULL pointer dereference in some random dissector when fed arbitrarily naughty pcap data. It's bad enough that I do almost all of my reverse engineering work inside various VMs that have strict isolation from the host. I'd have expected a Java-based program like JEB to be better at this, but apparently they got lazy and decided to just eval() the untrusted binaries...
I would not be entirely surprised if some state-level actor somewhere booby-traps their binaries with exploits like these to figure out who's looking at their stuff.
I have to kill gdb from outside the X server to do anything else
Given things like Log4Shell and Spring4Shell seems like there is a lot of software written in Java where authors just willingly add capability to execute random code and see nothing wrong with it.
Heck, SecurityManager has been basically a dead feature for ages. I'm stunned that JEB didn't start with a different solution.
Assuming sandbox is working correctly any parts with sideffects will probably not be very productive for deobfuscation anyway. Such automated decryption strategy would work best for purely functional parts of code. But the parts that interact with os and filesystem are either not part of decryption code (so no point executing) or if they are part of decryption they are probably the parts which try to defeat such automated decryption by detecting sandboxed/emulated environment and stopping decryption (again no point executing it without some manual intervention or very carefully designed fake environment simulating a specific target).
Whoever changed Java 18 to indirectly cause sandboxes to stop working - do they bear some responsibility here? Don't know the details of this particular case but have been burnt before by defaults changing to insecure before.