3 ms·
I hate inline escape sequences, but I hate ioctl/SetConsoleTextAttribute even more. I also think that if someone (including, of course, the bumbling fool known
by ElectricalUnion 3y ago
I hate inline escape sequences, but I hate ioctl/SetConsoleTextAttribute even more.
I also think that if someone (including, of course, the bumbling fool known as myself) ran something on my terminal I'm already toast even before the terminal misbehaves - because most sandboxes/mandatory access control systems are either a complete joke or disabled most of the time.
- gsuuon 3y agoYou don't even need to run something untrusted, just compromised console output is enough (from server logs, for example they mention python -m http.server)
- ElectricalUnion 3y agoYes, and it's "even better" that your average RCE because it's not running code on the potentially sandboxed server, but on the (statistically speaking not sandboxed) developer/admin machine with potentially privileged access to other machines and systems.