Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add rvim shell trick (restricted environment breakout) #410

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

LucasVanHaaren
Copy link

Hello,

I added to the rvim page a trick to get a shell through the poisonning of the ~/.vimrc file, It only works on older versions of rvim.

Let me know if anything is wrong.

Here is the link to the vuln discover thread : https://huntr.dev/bounties/d60e9e45-be06-40cb-99ad-d94ecdfb0fa4/

Thank you ❤️

@locaIhost
Copy link

Hi. Could you specify up to which version this works? 🌵

@LucasVanHaaren
Copy link
Author

Hi, sure !

According to the huntr.dev thread this trick works up to vim version 9.0.1440.
I had mentioned it on the page but not in this ticket 😄

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants