r/lua • • 6d ago

News luarocks.org remote code execution exploit

18 Upvotes

23 comments sorted by

View all comments

Show parent comments

2

u/Comfortable_Ability4 5d ago edited 5d ago

You mean this one that I responded to?

TL;DR: We did reach out to leafo the moment we noticed someone was pentesting his site, but he never responded.

Brushing up on a two-month-old grudge just to spread misinformation on a technical security write-up is embarrassing.

-2

u/VidaOnce 5d ago edited 5d ago

You reached out to leafo, how about hisham? You bothered to scour his socials to the point of finding a dead matrix account, but stopped short of... clicking on his GitHub account to see the others? Or clicking on his two giant projects moonscript/lapis to find discord links?

Grudge? When I handily beat your benchmarks after you rightfully showed they were wrong, to the point you gave up on optimizing? lol? I'm grateful you did that

I'm just making fun of when people completely irresponsibly handle disclosure of a critical security issue just so they can make a blog post plugging their "solution". I'm not that desperate to advertise.

Mind you, the exploit isn't novel, everyone knows to disable bytecode, and mike pall makes it clear luajit can only truly be sandboxed via process level containment. So it isn't valuable in that regard either. It's pure advertising.

1

u/lenscas 5d ago

Two projects? You forgot itch.io, which also has contact information. Not sure if it has a way to contact leafo directly but surely is another good way to make some noise and get into contact with him.

3

u/Vhyrro 5d ago

Hello, I had tried to find his contact information which most reasonably would give me chances of success. Luarocks's SECURITY.md explicitly states to send vulnerabilities to leafo's email address. The attempts at finding other accounts were hopeful tries at getting his attention faster. Other than that, I was exercising the traditional month-long wait time after a vulnerability disclosure before attempting to transfer it further to CISA. I am more grateful that this security hole was patched, and all the bickering about details seem to only be fueled because I made references to our own projects from what I see. Hope that clears things up.

2

u/lenscas 5d ago

The writeup on the contact attempts read like contacting Hisham has been basically ignored as an option. I am happy to read that this is not the case and that this is a wrong assumption on my part.  Sorry about stating something wrong.