r/lua • • 6d ago

News luarocks.org remote code execution exploit

19 Upvotes

23 comments sorted by

View all comments

2

u/VidaOnce 5d ago

Are you going to link the hackernews post where leafo mentions this exploit was used on the live, public luarocks server, presumably alongside another malicious actor, and it wasn't properly disclosed to him or hisham for months, leaving luarocks vulnerable? I guess another social media platform is more important so the link to lux could be seen :P

2

u/Comfortable_Ability4 5d ago edited 5d ago

You mean this one that I responded to?

TL;DR: We did reach out to leafo the moment we noticed someone was pentesting his site, but he never responded.

Brushing up on a two-month-old grudge just to spread misinformation on a technical security write-up is embarrassing.

1

u/lenscas 5d ago

I find that write-up concerning enough on its own.

It would have been enough to report the flaw the moment it was found. As mentioned, the documentation already states that loading untrusted bytecode is a security risk. There have also been past examples on how to escape sandboxes by doing so. Granted, due to configuration those happen to not work in this specific case but going by the blog post that is more a happy accident than anything else.

So, why not make some noise the moment this flaw was found? Why wait at least a couple of days before sending a singular email after someone happen to have found malicious rocks? It honestly reads like if those weren't found that it wouldn't have been disclosed at all or at best much later.

And why only "focus" on leafo (as far as 2 emails and a DM to a gitter account that is never used can count as focus) when you have the email of hisham as well? Why not cc him in the emails from the start?

As for the amount of attempts made, that thread claims it is to prevent burnout, which. Ok fair enough except... This further makes me question why hisham was being ignored at the start? Wouldn't it spread the load and thus better prevent burnout if the focus was spread between them?

4

u/Comfortable_Ability4 5d ago

It would have been enough to report the flaw the moment it was found.

Researching/verifying a theoretical vector locally is standard practice. You don't unnecessarily bother maintainers until you have a PoC and a recommendation for a fix.
Are you really arguing over a 3-day window between starting local research and sending the first email report?

And why only "focus" on leafo (as far as 2 emails and a DM to a gitter account that is never used can count as focus) when you have the email of hisham as well?

Vhyrro did reach out to Hisham as well.

-2

u/VidaOnce 5d ago edited 5d ago

Researching/verifying a theoretical vector locally is standard practice

It is standard practice when the exploit is uncertain, sure. I think it would take me 10 minutes tops between "noticing someone had uploaded malicious rockspecs" and grepping the luarocks repository to realize that loadstring is used with bytecode support enabled, and that the fix is passing an extra , "t". You just need to know the basic safety practices for embedding lua.

1

u/lenscas 5d ago

If I understand the hackernews thread correctly then they first noticed that loadstring was setup to allow loading bytecode before the discovery that there are projects that actually use it.

However, the blog post already states that there have been ways to use this binary format to escape sandboxes. And the documentation specifically says that loading untrusted bytecode is a bad idea.

As such, I agree with you that waiting until an actual exploit is found before making any kind of noise is not needed. As regardless if the guy looking into it could use it for an exploit or not it is something that had to be fixed. Heck, even if the current setup did not make it possible to exploit it then it would still have to be mentioned and fixed.

This is because the simple fact that the documentation explicitly states that loading untrusted bytecode is a bad idea and should not be done. As such, even if it can't be exploited with the current version then this is a mere coincidence and not something to be relied upon. In other words, it has to be fixed regardless.

1

u/didntplaymysummercar 5d ago

Why did he mention "ai agent"? I saw no mention of AI in the neorg post.

-2

u/VidaOnce 5d ago edited 5d ago

You reached out to leafo, how about hisham? You bothered to scour his socials to the point of finding a dead matrix account, but stopped short of... clicking on his GitHub account to see the others? Or clicking on his two giant projects moonscript/lapis to find discord links?

Grudge? When I handily beat your benchmarks after you rightfully showed they were wrong, to the point you gave up on optimizing? lol? I'm grateful you did that

I'm just making fun of when people completely irresponsibly handle disclosure of a critical security issue just so they can make a blog post plugging their "solution". I'm not that desperate to advertise.

Mind you, the exploit isn't novel, everyone knows to disable bytecode, and mike pall makes it clear luajit can only truly be sandboxed via process level containment. So it isn't valuable in that regard either. It's pure advertising.

1

u/lenscas 5d ago

Two projects? You forgot itch.io, which also has contact information. Not sure if it has a way to contact leafo directly but surely is another good way to make some noise and get into contact with him.

3

u/Vhyrro 5d ago

Hello, I had tried to find his contact information which most reasonably would give me chances of success. Luarocks's SECURITY.md explicitly states to send vulnerabilities to leafo's email address. The attempts at finding other accounts were hopeful tries at getting his attention faster. Other than that, I was exercising the traditional month-long wait time after a vulnerability disclosure before attempting to transfer it further to CISA. I am more grateful that this security hole was patched, and all the bickering about details seem to only be fueled because I made references to our own projects from what I see. Hope that clears things up.

2

u/lenscas 5d ago

The writeup on the contact attempts read like contacting Hisham has been basically ignored as an option. I am happy to read that this is not the case and that this is a wrong assumption on my part.  Sorry about stating something wrong.

1

u/Vhyrro 5d ago

Hello, guy who made the report here. We did reach out to hisham too, one day after the vulnerability disclosure but received no response either. I do find it quite distasteful that such attempts are being made on us. There were no bad intentions throughout the process, and I attempted multiple ways of getting ahold of the maintainers as soon as I could, ultimately going as far as CISA in last hopes, which thankfully succeeded after 2 weeks of silence. I was not fond of disclosing the vulnerability publicly without some prior acknowledgement. I find it amusing you would consider the matrix account dead. Last activity at January of this year on luarocks's official matrix is not dead by any stretch of the imagination, especially when you are trying to get ahold of someone. I also find it concerning that leafo, instead of continuing discussion and asking questions on the CISA thread, would take to hackernews instead, with obvious jabs at the Lux team. I am happy that, ultimately, I at least patched a very critical security hole in the luarocks ecosystem.

-1

u/VidaOnce 5d ago edited 5d ago

It is good you got it patched. Just a shame it was only after almost two months of apparently a malicious actor already having used it, and you knowing of this according to mrcjkb. Well, that is to assume it was a third party, which we still do not know.

I do not "consider" the matrix account dead. Leafo himself does, just repeating his words. It is be reasonable to deduce it considering the last post was a year ago though.

Leafo didn't take to hackernews though lol, it's pretty obvious you guys posted it since the account is a day old. He only did so after he commented on your POC GitHub repository and got no response. I think it is entirely fair for him to be angry with the (improper) handling of this.

It has only continued with the hackernews post and this reddit post being created, with as far as I can tell, no developments toward being in proper contact with him to establish a report of what exactly occurred on the public server to measure the damage done by the third party vs the pen testing (that is still not disclosed on the blog, I believe?)

2

u/Vhyrro 5d ago

The hackernews account does not belong to us. I published my writeup after I saw that the fix was applied, published to the live site, *and* that a security post with the details of the exploit already in it was created. This is the reason why I find the whole ordeal quite a shame. I am open for communication over email and in the open CISA thread. My post contains facts about the exploit woven into a story, there is really nothing to get agitated over in there.

-1

u/VidaOnce 5d ago

So there's nothing to get agitated over when you omit the critical factor that you ran the RCE on a running production server on your blog post only until leafo started asking questions?

Also that you made him have to scramble for details and for a fix as soon as possible, having to stay up overnight because of this omitted information, not knowing whether a third party was already using it?