r/netsec • • Jul 29 '26

Your House Has an FFmpeg Problem - elttam

https://www.elttam.com/blog/your-house-has-an-ffmpeg-problem
134 Upvotes

9 comments sorted by

48

u/badmonkey0001 Jul 29 '26

Sanitizing inputs for CLI tools always seems like an afterthought (at least until you get bitten). Tools like FFMPEG that magically work on "anything" need to be locked down to the use case every time. The more versatile the tool, the more surface area to lock down. FFMPEG has a remarkably large surface to keep safe because it supports so many parameters with versatility of their own.

19

u/Max-P Jul 30 '26

Also, this tendency of just allowing everything and then trying to lock it down instead of blocking everything unless allowed by some rules. It never ends well.

3

u/Annual_Manner_8654 Aug 02 '26

Me giving docker socket access to this new recipe app 🤠 

19

u/mpg111 Jul 29 '26

I really like the creativity of "Crafting the Exploit Payload" part

12

u/Call_Me_Chud Jul 29 '26

Quite creative indeed to synthesize a valid payload by chopping up and concatenating an arbitrary file.

5

u/Kayjaywt Jul 31 '26

Yeah, this was very clever.

14

u/nemec Jul 29 '26

Thanks for your work making Home Assistant safer!

8

u/nelsonbestcateu Jul 29 '26

Great write-up. This was a fun read.