Sourcehut account takeover via build logs (XSS in ansi2html)
Welcome to my first big impact vulnerability writeup!
I like good stories, so let me describe some background first. I recently had a ‘great’ idea (I know, I know, I should stop having these) to set up a sr.ht instance that would pay people for hosting their projects. You can find it shamelessly plugged in the timeline section, in case you want to try it or flame me for it on socials.
Anyway, the story. The first step was to clone some minimal subset of the sr.ht repos, and start hacking on it.
No NLP I tend to include the following statement in my vulnerability research submissions from this year. Make from it what you wish.
No NLP has been used in this research. The mistakes are all mine.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in