Alex Rivera | Logout

Surprising software vulnerabilities or exploits?

Asked 2009-07-18T23:01:54.727
26

What are the most strange/sophisticated/surprising/deeply hidden software vulnerabilities or exploits you have ever seen? Places in code where you thought that there is no danger hidden, but were wrong?

[To clarify: Everybody knows SQL injections, XSS or buffer overflows - bugs which often result from careless coding. But things like Ken Thompson hidden trojan (Reflections on Trusting Trust: http://cm.bell-labs.com/who/ken/trust.html), recent NULL dereference vulnerability in Linux kernel (http://isc.sans.org/diary.html?storyid=6820), or a complex attack on RNG using denial of service (http://news.ycombinator.com/item?id=639976) have disturbed me greatly.]

Update: Thanks all for answers, they were great. I had hard choice. Ultimately I decided to award the bounty to side channel/power monitoring attack. Nevertheless, all your answers combined show that I have to learn more about security, since it's a really deep subject :).

Edit
Report

2 Answers

21

Everyone does know about SQL injections, but one of the most surprising exploits I recently heard about was putting SQL injections into bar codes. Testers should be checking ALL inputs for malicious SQL. An attacker could show up at an event and crash their registration system, change prices at stores, etc. I think just bar code hacking in general was surprising to me. No wow factor here, just something else to be aware of.

EDIT: Just had a discussion where the idea of putting the SQL injection on a magnetic card strip was brought up. I guess you can put one anywhere, so test any and all input, especially from users and these kinds of data storage devices.

answered 2009-07-27T15:04:58.020
3

Extremely simple method to mess with your web application: If the application allows users to add pictures to profiles, messages board or blog posts, malicious user can set up image URL like '/Account/LogOut' (or any other valid local URL causing actions we don't want). If he manage to publish his profile/post/message "up to main page" - every user will be logged out immediately after logging in (the browser will execute te request to /Account/LogOut in context of the current user in order to download the image), so the page functionality will by serously damaged.

answered 2009-11-19T14:12:50.487

Your Answer