‹ BackHN Continuity

Thread

Sourcehut account takeover via build logs (XSS in ansi2html)

153 points · 29 comments · arusekk

  1. kwhitlock · · focus · HN ↗
    Build logs are such a tricky attack surface; sanitizing arbitrary build output is practically impossible without breaking useful formatting. Always assume untrusted input.
    1. jessebldr · · focus · HN ↗

      [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.