‹ BackHN Continuity

Thread

How one Twitch chat message became code execution on a streamer’s PC

67 points · 30 comments · tau255

  1. hahn-kev · · focus · HN ↗
    It seems wild to me that Twitch doesn't sanitize the messages on their backend. I'm sure that they sanitize them on their own UI. But considering how many people also consume messages via their API, they should also sanitize for them, defense in depth and all.
    1. calmingsolitude · · focus · HN ↗
      This makes absolutely no sense. The API returns the exact content of the message, and has no idea where it possibly might be displayed. It could be another browser, so html tags will need to be sanitized, but it might as well be the terminal, so ansi escape codes will need to be sanitized instead.
      1. rubendev · · focus · HN ↗
        Yes, you need to apply output encoding or sanitization at the place where it is being combined with another string. Otherwise you don’t know the encoding which is needed. Even for HTML you cannot do it on the backend, because you don’t know if it will be injected into HTML PCDATA context (tags) or in HTML attribute context.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.