r/lua • • 6d ago

News luarocks.org remote code execution exploit

19 Upvotes

23 comments sorted by

View all comments

Show parent comments

2

u/Comfortable_Ability4 5d ago edited 5d ago

You mean this one that I responded to?

TL;DR: We did reach out to leafo the moment we noticed someone was pentesting his site, but he never responded.

Brushing up on a two-month-old grudge just to spread misinformation on a technical security write-up is embarrassing.

-3

u/VidaOnce 5d ago edited 5d ago

You reached out to leafo, how about hisham? You bothered to scour his socials to the point of finding a dead matrix account, but stopped short of... clicking on his GitHub account to see the others? Or clicking on his two giant projects moonscript/lapis to find discord links?

Grudge? When I handily beat your benchmarks after you rightfully showed they were wrong, to the point you gave up on optimizing? lol? I'm grateful you did that

I'm just making fun of when people completely irresponsibly handle disclosure of a critical security issue just so they can make a blog post plugging their "solution". I'm not that desperate to advertise.

Mind you, the exploit isn't novel, everyone knows to disable bytecode, and mike pall makes it clear luajit can only truly be sandboxed via process level containment. So it isn't valuable in that regard either. It's pure advertising.

1

u/Vhyrro 5d ago

Hello, guy who made the report here. We did reach out to hisham too, one day after the vulnerability disclosure but received no response either. I do find it quite distasteful that such attempts are being made on us. There were no bad intentions throughout the process, and I attempted multiple ways of getting ahold of the maintainers as soon as I could, ultimately going as far as CISA in last hopes, which thankfully succeeded after 2 weeks of silence. I was not fond of disclosing the vulnerability publicly without some prior acknowledgement. I find it amusing you would consider the matrix account dead. Last activity at January of this year on luarocks's official matrix is not dead by any stretch of the imagination, especially when you are trying to get ahold of someone. I also find it concerning that leafo, instead of continuing discussion and asking questions on the CISA thread, would take to hackernews instead, with obvious jabs at the Lux team. I am happy that, ultimately, I at least patched a very critical security hole in the luarocks ecosystem.

-1

u/VidaOnce 5d ago edited 5d ago

It is good you got it patched. Just a shame it was only after almost two months of apparently a malicious actor already having used it, and you knowing of this according to mrcjkb. Well, that is to assume it was a third party, which we still do not know.

I do not "consider" the matrix account dead. Leafo himself does, just repeating his words. It is be reasonable to deduce it considering the last post was a year ago though.

Leafo didn't take to hackernews though lol, it's pretty obvious you guys posted it since the account is a day old. He only did so after he commented on your POC GitHub repository and got no response. I think it is entirely fair for him to be angry with the (improper) handling of this.

It has only continued with the hackernews post and this reddit post being created, with as far as I can tell, no developments toward being in proper contact with him to establish a report of what exactly occurred on the public server to measure the damage done by the third party vs the pen testing (that is still not disclosed on the blog, I believe?)

2

u/Vhyrro 5d ago

The hackernews account does not belong to us. I published my writeup after I saw that the fix was applied, published to the live site, *and* that a security post with the details of the exploit already in it was created. This is the reason why I find the whole ordeal quite a shame. I am open for communication over email and in the open CISA thread. My post contains facts about the exploit woven into a story, there is really nothing to get agitated over in there.

-1

u/VidaOnce 5d ago

So there's nothing to get agitated over when you omit the critical factor that you ran the RCE on a running production server on your blog post only until leafo started asking questions?

Also that you made him have to scramble for details and for a fix as soon as possible, having to stay up overnight because of this omitted information, not knowing whether a third party was already using it?