[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[O] RCE through Org-protocol and org-babel

From: Ring \<3 Rootkitty
Subject: [O] RCE through Org-protocol and org-babel
Date: Tue, 26 Feb 2019 16:31:22 +1100
User-agent: mu4e 1.0; emacs 27.0.50

Hi all,

Some time ago I discovered a method of executing remote code by
controlling the content sent over org-protocol, escaping the capture
template, and embedding a org-babel code block.

Details are outlined in the blog post bellow.

I don't really know if this is the right place to send it, but hey it's
best that people are aware that this is possible, even if it involves
user interaction to some extent.

Ring <3 Rootkitty

reply via email to

[Prev in Thread] Current Thread [Next in Thread]