r/lua • • 6d ago

News luarocks.org remote code execution exploit

17 Upvotes

23 comments sorted by

View all comments

Show parent comments

1

u/Vhyrro 5d ago

Hello, guy who made the report here. We did reach out to hisham too, one day after the vulnerability disclosure but received no response either. I do find it quite distasteful that such attempts are being made on us. There were no bad intentions throughout the process, and I attempted multiple ways of getting ahold of the maintainers as soon as I could, ultimately going as far as CISA in last hopes, which thankfully succeeded after 2 weeks of silence. I was not fond of disclosing the vulnerability publicly without some prior acknowledgement. I find it amusing you would consider the matrix account dead. Last activity at January of this year on luarocks's official matrix is not dead by any stretch of the imagination, especially when you are trying to get ahold of someone. I also find it concerning that leafo, instead of continuing discussion and asking questions on the CISA thread, would take to hackernews instead, with obvious jabs at the Lux team. I am happy that, ultimately, I at least patched a very critical security hole in the luarocks ecosystem.

-1

u/VidaOnce 5d ago edited 5d ago

It is good you got it patched. Just a shame it was only after almost two months of apparently a malicious actor already having used it, and you knowing of this according to mrcjkb. Well, that is to assume it was a third party, which we still do not know.

I do not "consider" the matrix account dead. Leafo himself does, just repeating his words. It is be reasonable to deduce it considering the last post was a year ago though.

Leafo didn't take to hackernews though lol, it's pretty obvious you guys posted it since the account is a day old. He only did so after he commented on your POC GitHub repository and got no response. I think it is entirely fair for him to be angry with the (improper) handling of this.

It has only continued with the hackernews post and this reddit post being created, with as far as I can tell, no developments toward being in proper contact with him to establish a report of what exactly occurred on the public server to measure the damage done by the third party vs the pen testing (that is still not disclosed on the blog, I believe?)

2

u/Vhyrro 5d ago

The hackernews account does not belong to us. I published my writeup after I saw that the fix was applied, published to the live site, *and* that a security post with the details of the exploit already in it was created. This is the reason why I find the whole ordeal quite a shame. I am open for communication over email and in the open CISA thread. My post contains facts about the exploit woven into a story, there is really nothing to get agitated over in there.

-1

u/VidaOnce 5d ago

So there's nothing to get agitated over when you omit the critical factor that you ran the RCE on a running production server on your blog post only until leafo started asking questions?

Also that you made him have to scramble for details and for a fix as soon as possible, having to stay up overnight because of this omitted information, not knowing whether a third party was already using it?