Data-only attacks are easier than you think (2024)

segfaultbuserr 17 points 7 comments September 23, 2026
www.usenix.org · View on Hacker News

Discussion Highlights (4 comments)

gumby

> Data-only attacks ... have long been considered too sophisticated and niche to pose a practical threat. I thought the whole point of fuzzing was an example of finding data-only attacks.

Terr_

> The attack effectively modifies only the arguments of the execve syscall I feel this checklist of shell-tools [0] is relevant, although the focus is more on how setuid is dangerous because you might not know the fancier arguments someone could supply. > GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems. [0] https://gtfobins.org/

joa-

This showed me that taint analysis is kind of slept on. Maybe we should invest in better tooling that allows us to reverse engineer with taint analysis easier. Do we think it is a UI problem? Of course over tainting is a thing, but maybe we can make it work with better UI.

burgerone

I'm positively surprised that their tool is not yet another LLM wrapper. The quality of research (and by extent HN submissions) has really plummeted since LLMs have become marginally useful

Semantic search powered by Rivestack pgvector
7,406 stories · 68,254 chunks indexed