‹ BackHN Continuity

Thread

How one Twitch chat message became code execution on a streamer’s PC

67 points · 30 comments · tau255

  1. hahn-kev · · focus · HN ↗
    It seems wild to me that Twitch doesn't sanitize the messages on their backend. I'm sure that they sanitize them on their own UI. But considering how many people also consume messages via their API, they should also sanitize for them, defense in depth and all.
    1. Rohansi · · focus · HN ↗
      How can you sanitize it in the backend? Do you just not allow sending messages with HTML tags in them?
      1. hahn-kev · · focus · HN ↗
        That, or no script tags, but that is quite hard as I understand.
      2. btilly · · focus · HN ↗
        No. You have rules for explicitly allowed HTML, and escape anything that could be a tag that does not follow the rules.

        This allows people to paste in rich content, but not things like <script> tags.

        1. Rohansi · · focus · HN ↗
          Pretty sure I saw someone shared that it was actually an <img> tag with onload set. Basically the same thing but just shows how unreasonable it is to expect Twitch to filter it for everyone. Also don't forget that people do livestream programming where there is a chance chat would include shared code snippets.
    2. calmingsolitude · · focus · HN ↗
      This makes absolutely no sense. The API returns the exact content of the message, and has no idea where it possibly might be displayed. It could be another browser, so html tags will need to be sanitized, but it might as well be the terminal, so ansi escape codes will need to be sanitized instead.
      1. rubendev · · focus · HN ↗
        Yes, you need to apply output encoding or sanitization at the place where it is being combined with another string. Otherwise you don’t know the encoding which is needed. Even for HTML you cannot do it on the backend, because you don’t know if it will be injected into HTML PCDATA context (tags) or in HTML attribute context.
    3. Ohentis · · focus · HN ↗
      I feel like trying to predict every way someone could fuck up a chat display is a fool's errand.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.