HNHacker News
TopNewBestAskShowJobs

oskarsv

565 karma · joined August 29, 2020

submissionscomments
oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
that electronSafeIpc API is actually not that interesting and a completely standard way to do things for ElectronJS apps.

No, I do agree - from my perspective C/C++ class bugs are more difficult. Maybe they see this as magic as well.

Still, it was painstaking work and in either case CountryX will easily surpass those difficulties.

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
please check out how much code MS Teams actually has, before statements like this :)

(it’s more than 30MB of compressed JS)

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
There is no timeline besides when I reported it and now minus 2wks. They never told me when the fix was deployed.

There is little value in going through the email chains to note each date:(. Final decision was made 2020-11-19

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
sure, add guest accounts to that and we are almost on the same page.

I can’t call this “spoofing” as there are many many things you can do wih it

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
only as a thought exercise. the ability to 'switch off the internet' (115 million daily active big corp users) is tempting, but no, not really :)
oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
I'm not an expert on Electron security!

But if not addressed to me, there is no need to pay, you can start here: - https://www.electronjs.org/docs/tutorial/security - https://github.com/electron/electron/security/advisories

As you can see there are plenty of considerations and pitfalls to take into account. Best option is to enable contextIsolation for everything.

Further, Electron security is closely tied to Chrome security so that is one deep rabbit hole

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
Yeah, although technically it's "out of scope", I think there are times when you should stop debating the technicalities and consider the business impact.

I mean, do you look at that demo and think "yeah, that's technically just 'important' let's fix it in 2 months"?

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
no, as you can see in the first demo it could be completely silent.

not saying you are safe - I don’t know :)

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
to simplify - no it’s not enabled

the real answer is more complicated as it is not necessarily a global setting and depends on what you call a “sandbox”

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
there are different levels of security for ElectronJS, some, like in this case are not enough.

I think it will take a long time before we can call ElectronJS secure. there are regular sandbox escapes and that is from what we know publicly

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
you can find both disclosure dates and versions in the report.

As for when it was fixed - I have no idea, as they never told me, one day it just was.

oskarsv··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
I wrote this. This is one of five similar reports for MS Teams.

Even outside RCE, just consider the impact of access to SSO tokens and wormability :)

oskarsv··on Remote Code Execution in Slack desktop apps
The app has been updated multiple times since, but you can debug Slack and other Electron apps to see the context they are running with. Electron apps merge desktop functionality with web and sometimes it's possible to find abusable functions - e.g. filesystem, leaking dangerous Electron objects etc.

In this case it was possible to abuse lack of context isolation to overwrite functionality (first part of the JS exploit). This changed function behaviour to return (leak) a BrowserWindow class (https://www.electronjs.org/docs/api/browser-window) when calling window.open(). A BrowserWindow class allows to instantiate a new window with your own security settings :)

Some of the current non-standard functions in Slack: https://imgur.com/a/OSjS0kJ

More info: https://www.electronjs.org/docs/tutorial/security

oskarsv··on Remote Code Execution in Slack desktop apps
thank you, appreciate some positivity :)
oskarsv··on Remote Code Execution in Slack desktop apps
Context matters. In this case it was a challenge because of previous research and I would've done it just for fun and the experience. I'm lucky I can afford to do that. Doesn't mean I don't value compensation.

In other cases maybe yes, maybe no - for some nonprofit, maybe someone needs help? are they a business and can they afford to compensate this kind of work? maybe it is some prominent product? there is no simple answer

oskarsv··on Remote Code Execution in Slack desktop apps
I don't live in a 'western country' nor do I make anything near a Silicon Valley salary
oskarsv··on Remote Code Execution in Slack desktop apps
Yes they should and I think I could. This exploit was more of a fun challenge.

I support and agree to everything you are saying. I love the community response. I too loathe the bug bounty asymmetry in power between corporations and reporters, but it exists.. by design. How do you imagine a researcher can 'demand' more money in this situation? They can choose the amounts arbitrarily and there is nothing legal or ethical you can do about it.

I haven't seen any proposals for real solutions - how would you ask this? How do you decide the amount for each company? Solutions, which do not bypass ethics or laws. I hope that 'the market' will solve this eventually and I think I at least raised awareness.

oskarsv··on Remote Code Execution in Slack desktop apps
high 4, low 5 figures

depends on exploit, program, company etc

oskarsv··on Remote Code Execution in Slack desktop apps
I agree with you. It's super low, but I and others will just ignore it in the future and ultimately they lose.

However, bug bounties are not a job. Nobody is forced or obligated to do anything. I'm giving them 'a pass' in the future :) It's great people are discussing this and surely it will improve things for future researchers.

I consider bug bounties like competitions. The 'prize money' is defined beforehand. You don't have to compete if you don't want it. You can also compete for the 'notoriety'. Knowing the stakes, do you complain after getting 'first place'?

Everything you own or do is only worth as much as someone is willing to pay for it, everything else is just speculation.

oskarsv··on Remote Code Execution in Slack desktop apps
Sure, absolutely they exist. But in my opinion they are the absolute minority. I've been in security for long enough to know that most people are good, otherwise we'd have major problems every day.

99% of people saying something about black markets or govt agencies have never really faced this decision or thought about it for more than 5 minutes. So it was a question - have you REALLY thought about it?

oskarsv··on Remote Code Execution in Slack desktop apps
I wrote that exploit & report. Just some thoughts on comments here.

Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming.

I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money - it was a fun challenge to chain it all together and I learned a lot from it.

The most outrageous part for me was the blog post I discovered by accident - it included no references or mentions (check archive.org). Both of the code snippets there are from my RCE reports. At the same time they were denying my requests for disclosure.

Of course, I understand that coordination mistakes like this happen, so I accept their apology and move on!

Evidence - original RCE video with huge CSS injection overlay: https://www.dropbox.com/s/11pv2ghdkw5g84b/css-rce-overlay.mo...