this post was submitted on 02 Jan 2024
4 points (100.0% liked)

Programmer Humor

35334 readers
1 users here now

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

founded 6 years ago
MODERATORS
 
top 4 comments
sorted by: hot top controversial new old
[–] SzethFriendOfNimi@lemmy.world 2 points 2 years ago (1 children)

Remember, always validate your inputs.

[–] draughtcyclist@programming.dev 1 points 2 years ago

Little Bobby Tables we call him.

[–] MyFeetOwnMySoul@lemmy.ca 0 points 2 years ago (1 children)

How does this exploit work? I understand that inputs were not sanitized, but what did the injected code do?

[–] powerofm@lemmy.ca 1 points 2 years ago

My guess would be the response text is passed through a rudimentary templating engine that looks for { and }. Somehow it must be processing the whole chat history. The templater fails at the unexpected braces in the code block and then just gives up (probably a try-catch ignores the error and sends the message anyway).