Hey everyone! Yesterday, I announced on Mastodon my third research paper that was accepted: https://infosec.exchange/@vmcall/117327103049106849. You may remember that earlier this year, I made this post: https://lemmy.world/post/41712400. In that, I was talking about randomly stumbling across cachestat... but if you read the paper, I also mention the inotify subsystem too 🧐. Well, I started digging into that and voila:

Announcing File Notification Attacks: Side-Channel Leakage from the File-Notification System on Linux, Android, Windows, and macOS, featuring KDE Plasma too!

We've found decades-old bugs on Linux, Android, and Windows (Microslop considers what we found an ✨️ undocumented feature ✨️, which got them nominated for the lamest vendor response pwnie award)

If you're interested, we made a full website showcasing the demos and paper - https://inoti.fyi/ -, which I'll summarize the Linux findings first here.

On Linux, watching a readable directory reports every event on a file inside it, even one the attacker cannot read directly - this is a bug that's still present on Linux today, although it's partially mitigated now (second-ever kernel disclosure and talking to maintainers!!!! SO EXCITING). The most severe case of this was with /dev/input, where every keypress generated notifications on /dev/input even across users (even across SSH users). While the key itself isn't leaked, the timing between it has been studied for over two decades.

Bypassing read permissions on Linux by mounting a watch on the file's parent directory.

On KDE Plasma 5 and 6, we found that the password dialog can be hidden by other windows, even on Wayland. We show an Authentication UI redress attack... this is still possible today, but we offer a workaround on the website (https://inoti.fyi/).

Here's the video of the attack in action (Debian 13, best distro, no FUD entertained, thanks): Watching /usr/bin/pkexec for accesses lets an attacker know when the password prompt is going to pop up, allowing them to draw a fake prompt over the real one. The visual difference in the dialogues here is deliberate.

I know this is the Linux community, but we still love hating on M$, so on Windows, watching the root directory (C:\) reports the full path of every file touched anywhere on the system, regardless of permissions, even across users 🙂. Microsoft considers this an ✨️ undocumented feature ✨️. The most severe case we found is leaking which websites another user visits in real time, a huge privacy issue that Microsoft, once again, said was an undocumented feature.

I'm just very excited that this research is being taken seriously by a lot of people, and I hope you find it cool too. There was no AI used in the findings, but we did use a bit of LLM tools to instrument some science stuff (measurements). Lots of people have asked me how we found these bugs (cough 'features' cough), asking whether an LLM can do this, or whether there were compiler tools... but the answer was a bit of creativity and some soda on my sofa late evening was all that was required to find all the cool things we report on the website in this paper. I don't think an LLM can come up with these creative findings - we've tried and it resorts back to patterns that we've made in the past, but it's unable to come up with new things, like we did in this work.

Feel free to ask me any questions! I'm very happy to be showing this to the Lemmy community. I posted this earlier to, what I believe, is a defederated community? !linux@lemmy.ml, but idk for sure.

no comments (yet)

sorted by: hot top controversial new old
there doesn't seem to be anything here