

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Oh oh, unsafe eval in a sandbox! (loadstring).
In my lua-like sandbox I disabled all escape hatches and unsafe functions physically by #ifndef SANDBOX. No IO, no FFI, no byte code loading, no memory funcs and such.
by rurban - Very good write up! Kudos.
I recently wrote about an RCE exploit in the game Project Zomboid (which uses Lua for mods), which also used loadstring as an initial entry point for the exploit chain, but since the Lua interpreter was fully Java, byte-code memory manipulation shenanigans were out of the question for me and I had to pivot in a more traditional way.
The fact that loadstring can also load straight up bytecode was news to me though, that's interesting to know.
by xx_ns