Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
|
wwsX0r's comments
login
wwsX0r
2 days ago
|
parent
|
context
|
next
[–]
| on:
RediShell: Critical remote code execution vulnerab...
But it says the lua script feature is open by default, so any authenticated (or 60k without auth) can run lua scripts -> use this RCE
reply
wwsX0r
2 days ago
|
parent
|
context
|
prev
|
next
[–]
| on:
RediShell: Critical remote code execution vulnerab...
The Lua interpreter in Redis doesn’t allow you to run regular code, you can’t event to “print”, not to talk about load libraries as in regular Lua interpreter. It’s a sanboxed one with very minimal operations you can do
reply
jamesgeck0
2 days ago
|
parent
|
next
[–]
The vulnerability appears to _be_ a Lua sandbox escape.
reply
wwsX0r
2 days ago
|
parent
|
context
|
prev
[–]
| on:
RediShell: Critical remote code execution vulnerab...
Surprisingly high numbers of exposed instances to the internet and unauth
reply
Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
reply