Data-Only Attacks Are Easier Than You Think

Data-only attacks, which corrupt program data without hijacking control flow, were long dismissed as too complex or application-specific to be practical. Researchers at USENIX Security 2024 present Einstein, an automated tool that generates such exploits with surprising ease by targeting syscall arguments. Their work shows that low-effort attackers can weaponize memory safety bugs to execute arbitrary code, challenging assumptions behind current defenses.
In our work, we show that these assumptions are all false: Exploitation requires neither extensive knowledge of the program semantics, nor the solving of complex data-flow constraints, nor the diversion of the control flow in a complicated (or even any) way.
- miellaby
> Data-only attacks, those that do not affect a program’s control flow, have long been considered too sophisticated and niche to pose a practical threat.
Leveraging user data to get malicious behavior is the basis of interpreter eval injection (php, js, perl, shell calls, SQL ...). These attacks are like 50 years old. What do I miss?
- lemmegetthis
Is this article saying that this AI tool has found 944 NEW unpatched exploits in nginx, and a comparable number in other commonly used server software?
Total 944
Table 2: Confirmed exploits for nginx.
- mgaldys4
Data-only attacks are somewhat low-hanging fruit. Classical static analysis could already find them before AI got this strong, and LLMs make identification even easier. But the real threat is risk buried in business logic, especially abuse of normal business logic. Take e-commerce refund abuse. Bug hunters would not even call it a risk, yet fraud rings have arbitraged millions off this kind of logic. And because the logic is legitimate business logic, it is very hard to detect.
- Terr_
> The attack effectively modifies only the arguments of the execve syscall
I feel this checklist of shell-tools [0] is relevant, although the focus is more on how setuid is dangerous because you might not know the fancier arguments someone could supply.
> GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
- gumby
> Data-only attacks ... have long been considered too sophisticated and niche to pose a practical threat.
I thought the whole point of fuzzing was an example of finding data-only attacks.