A Field Guide to Breaking In

Security mechanisms · Field guide

A Field Guide to Breaking In

How data becomes an instruction, a credential becomes authority, and a small failure becomes a larger breach.

A server receives a request. A database looks up a customer. A browser displays a comment. A developer installs a dependency. Nothing in that list sounds like an intrusion. Each action is ordinary work.

The danger begins when ordinary work carries something across a boundary it was supposed to respect: a value becomes part of a command; a packet changes where a processor goes next; a stolen cookie stands in for a person; a trusted update delivers hostile code.

“The attacker gained access” hides these differences. Access to what? With whose permissions? Can they read records, change records, make network requests, execute JavaScript in a browser, or run a program on a server? Those are different achievements, and the distance between them matters.

This guide follows eight attack families through those transitions. Historical incidents illustrate the mechanisms. The schematic chains are explanations, not reconstructions of a single incident.

First: what does remote code execution actually mean?

Remote code execution, or RCE, means that an attacker can cause a computer they do not directly operate to execute attacker-selected code. It does not necessarily mean a visible terminal, administrator privileges, or complete control of the network.

There are several routes. A memory flaw can redirect an existing program’s execution. An interpreter can evaluate externally supplied text as a program. A stolen administrator or deployment credential can authorize legitimate software to run an unauthorized program. A compromised dependency can arrive as code that the recipient deliberately executes.

The initial authority belongs to the process or account involved. A web service may be able to read its configuration, access its database and make outbound connections while being unable to modify the operating system. A sandbox can impose tighter limits. Reaching administrator privileges or escaping that sandbox requires another permission or another failure.

Execution chain:
remote inputexposed componentfailed boundaryattacker-selected behaviorcomponent’s existing permissions.

Reading this chain backward is useful. What valuable things can that component already do? Those are the first things at risk if it is subverted.

Entry pointFirst authority gainedWhat else is needed for server execution?
SQL injectionChange database operationsAn accessible command, extension, file-to-execution path or another flaw
Buffer overwriteCorrupt a process’s memoryA usable way to redirect execution despite protections
Cross-site scriptingExecute script in a site’s browser originA separate route from browser authority to server execution
Server-side expression injectionInfluence interpreter evaluationAccess to sufficiently powerful functions or objects
Stolen deployment credentialExercise a deployment identityPermission to deploy or administer the target
Server-side request forgeryMake requests from the serverA reachable resource that exposes further authority

1. Memory corruption: a packet changes the program

A network-facing program must interpret bytes. It may decode an image, parse a protocol message or unpack an archive. In native code, an error in a length, index or object lifetime can let that interpretation reach memory it should not touch.

In a stack-based buffer overflow, a write exceeds a buffer within a function’s stack frame. Depending on the layout, it can overwrite nearby values or saved control information, including a return address. A return address tells the processor where to resume after a function finishes. Corrupting it can therefore change the next instruction the processor executes. Many overwrites merely crash; useful control depends on what can be overwritten and on the defenses present. This differs from exhausting the stack through excessive recursion. MITRE’s classification.

The malicious input need not itself be an executable file. The receiving program supplies the execution machinery; the corruption changes its behavior.

A use-after-free is another route. An object is released, but the program later uses a stale reference to it. Its former memory may now contain a different object. Treating those contents as the original object can corrupt data or redirect a call through a function pointer. MITRE’s lifetime-error explanation.

Cisco’s 2018 Smart Install advisory provides a concrete remote example: improper validation of packet data could produce a buffer overflow, arbitrary code execution, a reload or a watchdog crash. The vulnerable software and enabled feature were prerequisites; merely sending traffic to any Cisco device was insufficient. The advisory describes a buffer overflow without establishing that every affected implementation was specifically stack-based. Cisco advisory.

Why does making the stack nonexecutable not end the problem? Because an attacker may redirect execution into code already present in executable memory. Code-reuse techniques arrange existing instruction sequences into unintended behavior. Address randomization makes their locations harder to predict; shadow stacks protect return addresses; control-flow checks restrict indirect branches. These measures obstruct exploitation without repairing the original memory error. Microsoft’s explanation of stack protection.

An out-of-bounds read is different again. Heartbleed exposed process memory through a missing bounds check in OpenSSL’s heartbeat handling. Its immediate effect was disclosure, not arbitrary execution. A disclosed key, session secret or memory address can nevertheless help another attack. OpenSSL’s original advisory.

The strongest stopping points are correct bounds and lifetimes, memory-safe implementations where practical, patched dependencies, and isolation of exposed parsers. Memory-safe code can still depend on unsafe foreign libraries. Isolation matters after prevention fails: Mozilla’s 2024 animation-timeline vulnerability enabled execution in a browser content process, an explicitly narrower result than unrestricted machine control. Mozilla advisory.

2. Injection: a value becomes an instruction

Injection is a family resemblance: externally supplied content enters a context where it can influence instructions. The interpreter determines both the mechanism and the authority gained.

SQL: the database obeys the application’s account

Imagine a customer search. The intended operation is fixed; the supplied customer name should be a value. If the application instead assembles query text from that name, input can alter the query’s structure. The database sees the resulting statement as a request from the application’s database account.

The attacker has acquired influence over an already-authorized speaker. Depending on permissions, this can expose records, alter data or defeat an application’s intended selection rules. Prepared statements keep values separate from query structure. Stored procedures help only when they also preserve that separation; internally concatenated dynamic SQL can recreate the flaw. Identifiers such as column names require controlled mappings rather than ordinary value parameters. OWASP’s SQL injection guidance.

SQL chain:
user-controlled valuealtered database statementapplication’s database permissionspossible additional execution capability.

That final step is conditional. SQL Server, for example, has a command-capable feature called xp_cmdshell. Microsoft documents it as disabled by default. If enabled and available to the compromised database identity, it can start an operating-system process under a service or configured proxy account. The database operation, permission to invoke that feature, and resulting operating-system privileges are three separate facts. Microsoft configuration guidance, execution and permissions documentation.

Even then, the database host may be a different machine from the web server. “SQL injection gives a shell on the website” skips both a capability boundary and a deployment question.

The US Department of Justice’s account of the Drinkman/Smilianets conspiracy describes SQL injection as a frequent initial route into corporate networks, followed by malware and further searches for financial information. It supports a multi-stage breach, not the claim that a database query directly accomplished every later action. DOJ sentencing account.

XSS: the browser becomes the execution site

Cross-site scripting occurs when attacker-controlled content reaches an executable browser context in a trusted site. The resulting script runs within that site’s origin. It can affect the page and perform actions available to the signed-in browser. This is browser-side script execution; it is not automatically native execution on the server.

The defense must match the context: safe rendering APIs, appropriate output encoding, and maintained sanitization where authored HTML is allowed. Content Security Policy adds a layer. Cookie flags can limit particular consequences, but do not make hostile script harmless. OWASP’s XSS guidance.

Twitter’s September 2010 incident illustrates the distinction. Content submitted as tweets could execute JavaScript in other users’ browsers; some caused involuntary retweets. Twitter said account information was not compromised in that incident. The documented behavior is already serious without converting it into an unsupported password-theft story. Twitter’s incident account.

Server-side evaluation: the interpreter has stronger hands

A template combines developer-authored instructions with supplied values. If supplied content becomes template source before evaluation, the engine may interpret attacker-selected expressions. Whether those expressions reach files, functions or operating-system commands depends on exposed objects and sandbox restrictions. Keep templates developer-controlled and reduce the evaluator’s capabilities. MITRE’s template-injection classification.

Expression-language injection is related, though not identical. Atlassian’s June 2022 Confluence advisory describes an actively exploited, unauthenticated OGNL expression-injection flaw permitting arbitrary code execution. Here the evaluation machinery was on the server, so the resulting authority was server-side. Atlassian advisory.

Log4Shell made this transition particularly surprising. An apparently passive logging operation could interpret externally influenced text through a lookup mechanism. In affected Log4j configurations, JNDI interactions with attacker-controlled endpoints could lead to arbitrary execution. A logging library had connected text processing to more powerful machinery. Apache also records that the initial fix was incomplete in some configurations: patch advice must follow maintained releases and subsequent findings, rather than freeze at the first emergency version. Apache security advisories.

SSRF and prompt injection: related boundaries, different powers

Server-side request forgery lets an attacker influence where a server sends requests. It borrows the server’s network position. That can expose internal services or credentials, but a request capability is not itself code execution. Destination restrictions must account for protocols, resolved addresses and redirects, alongside network egress controls. OWASP’s SSRF guidance.

Prompt injection attempts to make an AI system treat untrusted content as directions. Its interpreter is probabilistic; natural-language instructions and natural-language data lack the dependable separation provided by SQL value parameters. A hostile document causes consequential actions only through tools and permissions supplied by the surrounding application. Authorization, sensitive-data boundaries and validation of consequential actions therefore need enforcement outside the model. OWASP’s prompt-injection guidance.

The series examines an incident-specific chain in How the Boundaries Broke, and the human and agent dimensions in The Polite Customer.

3. Man-in-the-middle: controlling the route

An attacker operating a wireless access point or another part of the network path may observe unencrypted traffic, redirect connections or prevent delivery. Correctly authenticated TLS is designed to prevent that position from becoming silent access to protected content. Possession of the route does not supply possession of the server’s identity. TLS 1.3 specification.

The failure can instead involve certificate validation or the trust system behind it. In 2011, Mozilla reported active interception of Google connections using a fraudulent certificate issued by DigiNotar. The browser’s trust in an issuer had become the attacker’s advantage; Mozilla removed that trust. Mozilla’s DigiNotar advisory.

Identity chain:
attacker controls route + authentication failurefalse endpoint acceptedprotected conversation exposed.

Two different downgrades deserve separation. Replacing HTTPS with HTTP removes transport protection. Negotiating a weak legacy cryptographic mode concerns the protected protocol itself. HTTPS enforcement and sound TLS configuration address different parts of this problem.

HSTS tells browsers to require secure transport for a known protected site and disallows bypassing relevant certificate errors. A response header alone has an initial-discovery limitation; preloading addresses that bootstrap problem. HSTS specification.

Defenses preserve endpoint identity as well as encryption: maintained trust stores, correct certificate checks, secure transport and current protocol configurations. A padlock on an attacker’s own domain, however, certifies that domain. It does not certify the honesty of its owner.

4. Credential theft: the program works as designed

A password, session cookie, API token and deployment credential do not confer the same authority. Their scope determines the breach.

In adversary-in-the-middle phishing, a person visits an attacker-controlled site that relays interaction to the genuine service. The victim may complete a relayable MFA challenge, after which the proxy captures the authenticated session credential. Microsoft documented such a campaign in 2022, followed by mailbox access and financial fraud. The attacker hijacked a session; this does not establish that every form of MFA can be bypassed. Microsoft’s investigation.

WebAuthn credentials, including correctly deployed passkeys, are bound to a relying party and require validation of the origin. A lookalike site cannot ordinarily produce the assertion expected from the genuine origin. That protects authentication; it does not make a subsequently issued session immune to endpoint compromise or application flaws. WebAuthn’s origin-validation requirements.

How does this lead to running code remotely? Sometimes the stolen identity already has that permission. A deployment tool is expressly designed to place and start software on other machines. An attacker holding its credentials can misuse normal functionality. NSA and CISA document captured or default deployment-tool credentials being used for code execution and lateral movement. NSA/CISA advisory.

Credential chain:
stolen deployment identityauthorized administration interfaceattacker-selected programdeployment account’s permissions.

A read-only mailbox token has no equivalent power. Reaching a server from it requires an additional transition.

Separate ordinary identities from administration and deployment accounts; narrow credential scope and lifetime; protect endpoints and sessions; audit consequential uses. Recovery must address active tokens and sessions as well as passwords. Changing a password is not universally the same operation as revoking every session. Microsoft’s token-theft guidance.

5. Supply chain: hostile code arrives through a familiar door

A dependency, build artifact or update is meant to become running code. The attacker can exploit the recipient’s decision to trust its distribution path, without first corrupting the recipient’s memory or interpreter.

That makes the stages important: source repository, build workflow, release artifact, installation and execution are different places to establish or lose trust. Trusted publishing reduces dependence on long-lived publishing tokens; it does not guarantee that an authorized workflow produces harmless software. npm’s trusted-publishing documentation.

The xz backdoor is a deliberate compromise; an accidental defective update is a different kind of dependency risk. The project maintainer’s incident account documents the compromised releases and release-artifact issues. xz incident page.

The detailed mechanisms and defenses are already developed in How Trust Becomes Access and The Load-Bearing Volunteer. Here the essential question is: which person or process can introduce something the next stage will execute?

6. Denial of service: consuming the budget

An attacker need not read a secret or run a program to cause damage. Bandwidth, connection slots, CPU time, memory and queues are finite. Availability fails when incoming work consumes them faster than the system can recover.

HTTP/2 Rapid Reset illustrated how a protocol counter could differ from real resource use. Requests could be canceled while processing and cleanup work accumulated. A limit on simultaneous streams did not necessarily bound the server’s total burden. Cloudflare’s first-party analysis describes the resulting attacks and defensive tradeoffs. Cloudflare’s technical account.

The design lesson is to budget actual work: admitted requests, queued tasks, downstream operations and cleanup. Vendor fixes, timeouts and admission control address application or protocol costs; upstream filtering and absorption address volumetric traffic. Adding CPU cannot restore a network link already saturated before traffic reaches the machine.

7. Side channels: the secret changes observable behavior

Access controls can protect a secret’s direct output while its computation leaks information through timing or other observable effects.

Brumley and Boneh demonstrated recovery of private keys through timing observations of an OpenSSL server on a local network. Their result establishes a real remote timing attack under those conditions; it does not establish that any arbitrary Internet server exposes a recoverable key. Repeated observations, a vulnerable implementation and sufficient signal are prerequisites. Original USENIX paper.

Spectre exploits speculative execution. Operations that are later discarded can still leave microarchitectural traces, including cache effects, from which information may be inferred. The transient computation need not produce an architecturally permitted output to leave a measurable consequence. Original Spectre paper.

This is principally a disclosure route, not a generic remote shell. Relevant prerequisites depend on the variant and observation channel; many scenarios involve local processes or guests sharing hardware. Constant-time cryptographic implementation addresses secret-dependent timing. Spectre also requires suitable processor, compiler and operating-system mitigations and isolation. Linux’s Spectre documentation.

8. Social engineering: someone lends their authority

A person can reset an account, approve a payment, install software or grant access. Social engineering tries to make them exercise that authority under a false understanding of identity, purpose or urgency.

The exploited boundary may be a help desk’s recovery process rather than a login screen. CISA and the FBI’s Scattered Spider advisory documents social-engineering methods targeting organizations and their support functions. Strong login protection loses value if recovery can be persuaded to replace it. CISA/FBI advisory.

Defenses include independently verifying consequential requests, protecting recovery and separating approval from the person or channel making a request. The longer treatment in The Polite Customer examines persuasion across humans and agents.

What AI changes

AI can help people interpret unfamiliar software, write routine code, translate persuasive messages and organize repeated attempts. For defenders it can assist code review, vulnerability investigation and patch development. The effect differs by family: finding a lifetime error, impersonating a colleague and selecting an expensive request are different tasks.

There is concrete evidence of both offense and defense. Anthropic reported an AI-assisted espionage campaign involving extensive automation, while also describing errors and human involvement. That is a supplier’s investigation of activity visible to it, not independent proof that an agent reliably compromises arbitrary organizations. Anthropic’s incident report.

DARPA reported that AI Cyber Challenge systems found and patched vulnerabilities in its competition, including previously unknown flaws. This demonstrates useful capability in the tested setting; it does not make every generated patch correct or establish universal autonomous defense. DARPA’s results.

AISI’s research adds a measurement caution: more test-time compute changed observed success and the difficulty of cyber tasks agents could complete. A benchmark score must be read alongside its budget, tools and test environment. A low-budget failure is not necessarily a capability ceiling; a laboratory success is not a guarantee against an unfamiliar production system. AISI’s evaluation analysis.

My engineering inference is that cheaper analysis and iteration can increase pressure on reachable weaknesses. The permissions remain concrete. A model needs an interface through which its output can affect a system; a document can become dangerous to an agent when that agent holds tools and credentials. The defense is therefore partly about what the surrounding software allows a plausible-looking suggestion to do.

The question to carry into the next incident

These families overlap. A phishing message may steal a deployment token; a deployment may introduce a malicious library; a memory leak may reveal a session; an SSRF flaw may expose an internal administration endpoint. A breach is often a chain whose links grant different kinds of authority.

This guide is selective. Broken authorization, cryptographic failures and other families also matter. In particular, an authenticated user may access another user’s records because the application fails to check permission, even when its queries are safely parameterized. Fixing one boundary does not imply that the others hold.

When the next report says an attacker “ran code on a remote server,” ask what supplied the execution mechanism. Was it a corrupted program, an overpowered interpreter, a stolen administrative identity or a trusted distribution channel? Then ask which account ran the code, what it could reach, and which further transitions the evidence actually establishes.

Those questions turn an alarming phrase into an explanation. They also reveal where a defender could have stopped the chain.

Research note: historical examples are attributed to original advisories, standards, research papers or first-party incident reports linked at the point of use. General chains explain mechanisms and are not claims that every incident followed every step. Supplier reports and controlled evaluations are identified as such. Researched and drafted with Codex, 9 October 2026.

Comentários

Mensagens populares deste blogue

How Trust Becomes Access

Where The Schooling Went

The Completion

How an AI Agent Works