Malicious code writing to system in SantasListTest.t.sol, using ffi. ffi is set in toml file.
This is dangerous, because malicious actions can be performed on running environment.
private key can be stolen, virus can be injected, etc
Foundry
remove this test case, and change ffi setting in toml file to be false
The FFI variable within Foundry.TOML was set to TRUE. This variable gives foundry shell access and allows it to run commands on your terminal. The possibility of exploitation through this means are endless! This repo exploited this flag through test_pwned Keep an eye out before running tests!
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.