{"id":465,"date":"2011-02-11T13:45:20","date_gmt":"2011-02-11T21:45:20","guid":{"rendered":"http:\/\/www.outflux.net\/blog\/?p=465"},"modified":"2011-02-12T08:44:29","modified_gmt":"2011-02-12T16:44:29","slug":"shaping-the-direction-of-research","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2011\/02\/11\/shaping-the-direction-of-research\/","title":{"rendered":"shaping the direction of research"},"content":{"rendered":"<p>Other people have <a href=\"http:\/\/askubuntu.com\/questions\/25880\/am-i-vulnerable-to-recent-exploits-using-usb-sticks-and-automount\/25881#25881\">taken notice<\/a> of the recent &#8220;auto-run&#8221; attack research against Linux. I was extremely excited to see Jon Larimer publishing this stuff, since it ultimately did not start with the words, &#8220;first we disabled <a href=\"http:\/\/en.wikipedia.org\/wiki\/NX_bit\">NX<\/a>, <a href=\"http:\/\/en.wikipedia.org\/wiki\/ASLR\">ASLR<\/a>, and (SELinux|AppArmor) &#8230;&#8221;<\/p>\n<p>I was pretty disappointed with last year&#8217;s Blackhat conference because so many of the presentations just rehashed ancient exploitation techniques, and very few actually showed new ideas. I got tired of seeing mitigation technologies disabled to accomplish an attack. That&#8217;s kind of not the point.<\/p>\n<p>Anyway, <a href=\"http:\/\/www.youtube.com\/watch?v=ovfYBa1EHm4#t=90\">Jon&#8217;s research<\/a> is a step in the right direction. He defeats ASLR via brute-force, side-steps NX with ret-to-libc, and finds policy holes in AppArmor to accomplish the goal. I was pleased to see &#8220;protected by <a href=\"http:\/\/en.wikipedia.org\/wiki\/Position-independent_code#Position-independent_executables\">PIE<\/a> and <a href=\"http:\/\/apparmor.net\/\">AppArmor<\/a>&#8221; in his slides &#8212; Ubuntu&#8217;s hardening of evince was very intentional. It has proven to be a dangerous piece of software, which Jon&#8217;s research just further reinforces. He chose to attack the difficult target instead of going after what might have been the easier thumbnailers.<\/p>\n<p>So, because of this research, we can take a step back and think about what could be done to improve the situation from a proactive security perspective. A few things stand out:<\/p>\n<ul>\n<li>GNOME really shouldn&#8217;t be auto-mounting anything while the screen is locked (LP: #<a href=\"https:\/\/launchpad.net\/bugs\/714958\">714958<\/a>).<\/li>\n<li>AppArmor profiles for the other thumbnailers should be written (LP: #<a href=\"https:\/\/launchpad.net\/bugs\/715874\">715874<\/a>).<\/li>\n<li>The predictable ASLR found in the NX-emulation patch is long over-due to be fixed. This has been <a href=\"http:\/\/www.mail-archive.com\/kernel@lists.fedoraproject.org\/msg00561.html\">observed<\/a> repeatedly before, but I hadn&#8217;t actually opened a bug for it yet. Now I have. (LP: #<a href=\"https:\/\/launchpad.net\/bugs\/717412\">717412<\/a>)<\/li>\n<li>Media players should be built PIE. This has been on the <a href=\"https:\/\/wiki.ubuntu.com\/SecurityTeam\/Roadmap#Unscheduled%20Wishlist%20Items\">Roadmap<\/a> for a while now, but is not as easy as it sounds because several of them use inline assembly for speed, and that can be incompatible with PIE.<\/li>\n<li>Consider something like <a href=\"http:\/\/grsecurity.net\/pipermail\/grsecurity\/2009-October\/000998.html\">grsecurity&#8217;s GRKERNSEC_BRUTE<\/a> to slow down execution of potentially vulnerable processes. It&#8217;s like the 3 second delay between bad password attempts.<\/li>\n<\/ul>\n<p>Trying to brute-force operational ASLR on a 64bit system, though, would probably not have worked. So, again, I stand by my main recommendation for security: use 64bit. :)<\/p>\n<p>Good stuff; thanks Jon!<\/p>\n<p style='text-align:left'>&copy; 2011, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Other people have taken notice of the recent &#8220;auto-run&#8221; attack research against Linux. I was extremely excited to see Jon Larimer publishing this stuff, since it ultimately did not start with the words, &#8220;first we disabled NX, ASLR, and (SELinux|AppArmor) &#8230;&#8221; I was pretty disappointed with last year&#8217;s Blackhat conference because so many of the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,18,6,14,19,12],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/465"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=465"}],"version-history":[{"count":4,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/465\/revisions"}],"predecessor-version":[{"id":468,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/465\/revisions\/468"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}