First Flight #5: Santa's List

Beginner FriendlyFoundry
100 EXP
Submission Details
Severity: high
Valid

`SantasListTest: testPwned` executes arbitrary operation on caller machine, can take control over the machine to drain funds or leak info

Updates

Lead Judging Commences

Equious Admin
10 months ago
InAllHonesty Lead Judge 10 months ago
Submission Judgement Published
Validated
Assigned finding tags:

test_pwned FFI vulnerability

The FFI variable within Foundry.TOML was set to TRUE. This variable gives foundry shell access and allows it to run commands on your terminal. The possibility of exploitation through this means are endless! This repo exploited this flag through test_pwned Keep an eye out before running tests!

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.