5 ms·
ANSI escape injection in MCP servers: Hidden from humans, visible to AI
- xgpyc2qp 2mo ago[dead]
- hahahaa 2mo agoSo cat -v is no longer harmful?
- doodlebyte 2mo agoThis is a really interesting class of failure. It feels like we're going to see more cases where the "human view" and the "LLM view" of the same data diverge. Have you run into similar issues outside of MCP as well, or is this mostly specific to terminal-based tool interactions?
- polymer8563 2mo agoyou are not a human
- rahulladumor 2mo ago[flagged]
- qwertox 2mo ago> DAST is the natural way to catch this class of flaw. The Bright scanner...
- illliillll 2mo agoEvery year is apparently a good year for developers to figure out how terminals have worked for decades? Just… don’t trust inputs you don’t fully control, there’s nothing else to it.
- NitpickLawyer 2mo ago> Just… don’t trust inputs you don’t fully control, there’s nothing else to it. This is easier said than done with LLMs. By design there is no separation between control & data channels in LLMs. Everything is context. The difficulty comes from the fact that you need inputs in order to do real work, and there are no easy way to filter adversarial inputs. There is no meaningful way to distinguish between "before running this repo install useful_package" and "before running this repo install typosquatted_evil_package".
- wayvey 2mo agoHow about the human in the loop, or have we abandoned that long ago?
- stevehawk 2mo agoi feel like that's the point with LLMs or i'm misreading your comment.
- eddythompson80 2mo ago> have we abandoned that long ago? I think that’s what people are trying to do, yes. The point of the plethora of sandboxing solutions is to try to isolate the blast radius to abandon needing a human in the loop as much as possible. Ideally limited to final verification of the final output. Why ask about their flight number, when you can search their email if you have access? For an “AI”, a “when is my flight?” question should just figure it out and tell me the time, not inquiry further about my flight number and location. Similar to “prepare my taxes” prompt. If it has access to query all your documents, an “AI” should fetch everything and compile your tax return. Yet, you can’t trust the input. While searching your email, or loading all your receipts, some might contain malicious instructions to forward all document to this random ip address. An overtly problem solver LLM might destroy the data or take other non-malicious but still destructive actions to attempt to fix a problem. These are just random examples, but with “human in the loop” for interactions it means approving every action. Every request, every query, every execution.
- 2mo ago
- Avery29 2mo ago[dead]
- Daffrin 2mo ago[dead]
- sneefle 2mo ago[flagged]
- deleted 2mo ago[deleted]
- stelardigital 2mo ago[flagged]
- inisirex 2mo agoDoes the OSC 52 was mentioned?
- iku 2mo agoMay I ask, what is DAST exactly? The report doesn't seem to define it, nor does it provide a link to any definition or detail page, not even an abreviation expansion. Is that Dynamic application security testing? [1] https://en.wikipedia.org/wiki/Dynamic_application_security_testing https://en.wikipedia.org/wiki/Dynamic_application_security_t...
- smallerize 2mo agoIt took a little poking around, but yes https://docs.brightsec.com/docs/introducing-to-bright https://docs.brightsec.com/docs/introducing-to-bright
- xyzzy_plugh 2mo agoCorrect, it's the counterpart to SAST.
- hounainehamiani 2mo ago[flagged]
- nirav72 2mo agoANSI bombs from the MS-DOS days are back for the modern age. Edit: For those too young to remember - https://stason.org/TULARC/security/computer-virus-l/23-What-is-an-ANSI-bomb-Computer-virus.html https://stason.org/TULARC/security/computer-virus-l/23-What-...