‹ BackHN Continuity

Thread

How one Twitch chat message became code execution on a streamer’s PC

67 points · 30 comments · tau255

  1. hahn-kev · · focus · HN ↗
    It seems wild to me that Twitch doesn't sanitize the messages on their backend. I'm sure that they sanitize them on their own UI. But considering how many people also consume messages via their API, they should also sanitize for them, defense in depth and all.
    1. Rohansi · · focus · HN ↗
      How can you sanitize it in the backend? Do you just not allow sending messages with HTML tags in them?
      1. btilly · · focus · HN ↗
        No. You have rules for explicitly allowed HTML, and escape anything that could be a tag that does not follow the rules.

        This allows people to paste in rich content, but not things like <script> tags.

        1. Rohansi · · focus · HN ↗
          Pretty sure I saw someone shared that it was actually an <img> tag with onload set. Basically the same thing but just shows how unreasonable it is to expect Twitch to filter it for everyone. Also don't forget that people do livestream programming where there is a chance chat would include shared code snippets.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.