An exploit takes advantage of a vulnerability. The vulnerability is the flaw. The exploit is the tool or technique that uses it. A buffer overflow in a web server is a vulnerability. A crafted HTTP request that triggers the overflow is the exploit. Exploits range from a few lines of Python to complex chains that bypass multiple defenses. Some are sold on underground markets for millions. Others are published freely after a vendor patches the flaw.
Exploits target software, hardware, and people. Software exploits are the most common. They hit unpatched systems, misconfigured services, and zero-days that nobody knew about. Hardware exploits target firmware and microprocessors, like Spectre and Meltdown. Social exploits manipulate people into granting access. The lifecycle of an exploit starts with discovery, moves to weaponization, and ends when the vendor patches. The window between discovery and patch is dangerous. Attackers race to exploit before defenders can update. Zero-days are the most valuable because defenders have no warning. Most breaches do not use zero-days. They use known vulnerabilities that were never patched. The exploit was available for months. Nobody applied the fix.
Exploit categories
- Remote — works over a network without user interaction
- Local — requires access to the target machine
- Client-side — targets browsers, email clients, and documents
- Zero-day — exploits a vulnerability with no available patch
Patching is boring. It is also the single most effective defense against exploits. Most attackers use what already works.
Comments (2)
Leave a comment