Arbitary commands are allowed to run on host's machine. This leads to possible malware.
Foundry cheatcode ffi
is enabled, which allows arbitary commands to run on host's machine. The testPwned
test allows creating of a file on host's machine.
Creation of empty file.
Manual review
Disable ffi by setting ffi=false
in foundry.toml
The FFI variable within Foundry.TOML was set to TRUE. This variable gives foundry shell access and allows it to run commands on your terminal. The possibility of exploitation through this means are endless! This repo exploited this flag through test_pwned Keep an eye out before running tests!
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.