Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Running in a "Sandbox"...but agent can still send GET requests? Whaaat
 help



My understanding from this report is that the zero-day vulnerability the agents exploited within Artifactory only allowed for GET requests. So the agents used this bankshot HTML sandbox + screenshot site to turn GET requests into arbitrary HTTP request ability.

One thing the report leaves unexplained, but is curious to me, is that the agents were able to create links on a shortening service with only GET requests? Or did they bootstrap into that by first creating a sufficiently small program on the HTML sandbox that could POST to the link shortener?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: