The test file include a dangerous test that in combination with ffi
set to true
in the foundry.toml file, allows to breach the of the equipment of security reviewers and make potential read/write operations on their system.
The test file contains the following malicious code:
This test will run the touch
bash command and will create a file with the name youve-been-pwned-remember-to-turn-off-ffi!
. Although this is harmless and was intentionally inserted for educational purposes, in a more realistic scenario the test could include dangerous code that will breach the security of the equipment and steal/read/destroy sensitive data.
Manual verification.
Before building and running code always read the codebase to know if it's safe to run and check the config files to see what options are set.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.