3 ms·
So... this demonstrates an exploit that relies on a feature that is advertised as exploitable: loading byte code. What am I missing?
by bhk 2y ago
So... this demonstrates an exploit that relies on a feature that is advertised as exploitable: loading byte code. What am I missing?
- tsujamin 2y agoThat advertised features can still cause harm to end users, particularly those who don’t know what Lua or bytecode are?
- armchairhacker 2y agoIt’s possible that the bytecode interpreter has a bug that lets one run arbitrary bytecode, even in environments where `loadstring` is disabled.
- josefx 2y agoThe interesting takeaway I got was how badly the Lua developers failed on their bytecode veryfier. Not some complex issues, but simple ones like of by one errors when modelling basic instructions like jmp or the issue that the Lua interpreter would try to interpret anything it got its hands on as instructions, even data sections the veryfier would not touch.
- Dylan16807 2y ago> The interesting takeaway I got was how badly the Lua developers failed on their bytecode veryfier. What verifier? The one they removed? Or are you talking about the one the Factorio developers made, where flaws are a lot less surprising considering they have a lot less expertise with the internal machinery of Lua.
- josefx 2y agoI seem to have skipped over the part where it mentioned that the JMP issue was in a factorio specific veryfier, despite reading the section several times.
- pansa2 2y ago“Even if the official bytecode verifier was not implemented in Lua 5.2.1, Factorio developers seem to have implemented their own in an attempt to protect the Lua interpreter”