• 请不要在回答技术问题时复制粘贴 AI 生成的内容
xcatliu
V2EX  ›  程序员

发现可以在 LeetCode 的机器上运行一些脚本

  •  
  •   xcatliu ·
    xcatliu · Jan 23, 2016 · 4632 views
    This topic created in 3793 days ago, the information mentioned may be changed or developed.
    12 replies    2016-01-24 22:25:18 +08:00
    xcatliu
        1
    xcatliu  
    OP
       Jan 23, 2016
    想了想, GitHub 被我删了,免得被大家玩坏了。。。

    已经汇报给 LeetCode 官方
    xcatliu
        2
    xcatliu  
    OP
       Jan 23, 2016   ❤️ 1
    Hi,

    First, thanks for reporting to us and deleting the github repo. We do appreciate that you take the time to report us and taking some possible security holes offline so evil minds won't take advantage of this to do something possibly malicious.

    I do realize that you are able to run shell commands, and this is perfectly okay. You can even run `cat /etc/passwd` and that's allowed. The reason is everything is run inside a sandbox which would not affect the host system. However, I do prefer not to show the internal working of how the user code is run as shown in the `ps aux` command, which may tell something to the user more than he/she needs to know.
    virusdefender
        3
    virusdefender  
       Jan 23, 2016
    只能说 leetcode 应该是虚拟机运行的,有沙箱但沙箱限制的太松了
    mzer0
        4
    mzer0  
       Jan 24, 2016
    @xcatliu 能解释一下技术原理吗?
    dndx
        5
    dndx  
       Jan 24, 2016
    xcatliu
        6
    xcatliu  
    OP
       Jan 24, 2016
    @virusdefender 是, LeetCode 不担心你能运行 shell 脚本,只是怕你了解运行模式之后,影响到了解题的思路
    xcatliu
        7
    xcatliu  
    OP
       Jan 24, 2016
    @mzer0 大部分语音都有执行 shell 命令的方法吧
    xcatliu
        8
    xcatliu  
    OP
       Jan 24, 2016
    @dndx 是,别滥用即可
    Arthur2e5
        9
    Arthur2e5  
       Jan 24, 2016
    Delbert
        10
    Delbert  
       Jan 24, 2016 via iPad
    leetcode 本身还有 shell 专区的,本身就不是漏洞吧……
    xcatliu
        11
    xcatliu  
    OP
       Jan 24, 2016
    @Delbert 我也是这么问 LeetCode 的。。
    vanxining
        12
    vanxining  
       Jan 24, 2016 via Android
    LeetCode 创始人似乎是能说中文的?
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   3066 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 71ms · UTC 06:27 · PVG 14:27 · LAX 23:27 · JFK 02:27
    ♥ Do have faith in what you're doing.