Hackers can take full control of online compilers through a RCE exploit (2018)
serhack.me
serhack.me
EDIT: Oh nevermind, it sounds like they're pointing out that you can just upload malware.
But he actually is talking about online compilers that execute the code - he just runs `system("ls")`. What a waste of everyone's time.
##teamcity[setParameter name='foo' value='bar']]
or ##vso[task.setvariable variable=foo]bar
From any package in your deps, a simple console output can set any pipeline variable. CI pipelines are a security nightmare with modern dependency chains.I wrote that post two years ago and at least in 2 environment, there was no sandbox or under Docker. I remember that I found an interesting environment that an interesting script.
The script parsed the input file and then chose if it could be compiled or not. Well, it's really easy to circumvent that.
In 2020, I would be impressed to see someone shipping such application without sandbox/VM.
To be fair, docker is great, but I remember a few warnings about how users could get root access to the "host" machine. It's containers, not VMs.
AWS doesn't offer to run your docker container on a Linux instance shared with other customers' containers. VMs are the correct abstraction for secure isolation, not docker.
I think the article should have focused more on this as it's the most interesting and important part. execle and system are not really interesting, to paraphrase verroq: that just goes from arbitrary code execution to arbitrary code execution.
And disabling execle by recompiling library wont work, since you could still do a syscall "manually" with inline assembly.
I reported that to developers and they found that I could have access to sensible data.
Thanks for the tips on the article!
#include </etc/hostname>
#include </etc/hosts>
#include </etc/passwd>
If you get some info about the system/user the process is running as, you can even try something like #include </root/.ssh/id_rsa>
#include </root/.bashrc>
#include </root/.gitcredentials>
etc