logoalt Hacker News

Luarocks.org remote code execution exploit

22 points • by cupcakerob • yesterday at 8:13 PM • 1 comment • view on HN

Comments

rurban • today at 6:12 AM

Oh oh, unsafe eval in a sandbox! (loadstring).

In my lua-like sandbox I disabled all escape hatches and unsafe functions physically by #ifndef SANDBOX. No IO, no FFI, no byte code loading, no memory funcs and such.

cupcakerob • yesterday at 8:13 PM

[dead]