3 ms·
They sadly do not pop a shell.
by nilsherzig 2y ago
They sadly do not pop a shell.
- TZubiri 2y agoYeah, they did? Inside the container, they ran ls /.
- MeetingsBrowser 2y agoKind of like saying you popped a shell on replit because you ran ls. ChatGPT doesn't give direct access in the UI to the sandboxed environment, but ultimately you are still in a sandboxed environment designed to run arbitrary stuff. The article even says so if you read all the way to the end.
- TZubiri 2y agoI mean the same way you ran ls, you could run /bin/bash? Which is kind of pointless because the ls command is probably executed through a shell anyways. So technically correct. But getting root or running a shell usually means you can run arbitrary commands, which is a check here (albeit I wouldn't say there's root access)
- MeetingsBrowser 2y agoThere is no security implication for running /bin/bash in a service that provides you a sandbox environment to run arbitrary shell commands in. It is like reporting that AWS lambda is susceptible to arbitrary code execution.
- TZubiri 2y agoYes, I too read the article. But he did run a shell
- marcofigueroa 2y agoYeah I did :)