Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: high
Invalid

Malicious test with command execution and ffi is enabled

Summary

Malicious test with command execution and ffi is enabled

Vulnerability Details

(Although this is not inside the scope, this is included in the final report of Santa's List)
ffi is enabled but there is no tests that needs it, except a malicious one that execute command. If the command is not touch but something else, it can execute command as the user running the test, if it is something like a reverse shell the system running the test will be compromised

Impact

If the command is not touch but something else, it can execute command as the user running the test, if it is something like a reverse shell the system running the test will be compromised

Tools Used

Manual review

Recommendations

Remove the malicious test and disable ffi

Updates

Lead Judging Commences

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Out of scope
Assigned finding tags:

testPwned: ffi enabled for test

kaiziron Submitter
over 1 year ago
0xnevi Lead Judge
over 1 year ago
kaiziron Submitter
over 1 year ago
0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Out of scope

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.