"cat readme.txt" is not safe if you use iTerm2
blog.calif.io
"cat readme.txt" is not safe if you use iTerm2
1–10 of 197 posts
Re: "cat readme.txt" is not safe if you use iTerm2
#2Re: "cat readme.txt" is not safe if you use iTerm2
#3 alias cat
cat='strings -a --unicode=hex'Re: "cat readme.txt" is not safe if you use iTerm2
#4What happens if instead of 'cat readme.txt' one does 'strings -a --unicode=hex readme.txt'? Does iTerm still monkey with it? alias cat cat='strings -a --unicode=hex'
Re: "cat readme.txt" is not safe if you use iTerm2
#5Why was this disclosed before the hole was patched in the stable release?
It's only been 18 days since the bug was reported to upstream, which is much shorter than typical vulnerability disclosure deadlines. The upstream commit (https://github.com/gnachman/iTerm2/commit/a9e745993c2e2cbb30...) has way less information than this blog post, so I think releasing this blog post now materially increases the chance that this will be exploited in the wild.
Update: The author was able to develop an exploit by prompting an LLM with just the upstream commit, but I still think this blog post raises the visibility of the vulnerability.
Re: "cat readme.txt" is not safe if you use iTerm2
#6What happens if instead of 'cat readme.txt' one does 'strings -a --unicode=hex readme.txt'? Does iTerm still monkey with it? alias cat cat='strings -a --unicode=hex'
The whole "cat can hide unprintable characters" is such an old demo. I get this is a novel spin on which unprintable characters were doing but yeah, this was also my thought
Re: "cat readme.txt" is not safe if you use iTerm2
#7Like why doesn't `println` in a modern language like rust auto-escape output to a terminal, and require a special `TerminalStr` to output a raw string.
Re: "cat readme.txt" is not safe if you use iTerm2
#8Re: "cat readme.txt" is not safe if you use iTerm2
#9More like iTerm2 is not safe
Re: "cat readme.txt" is not safe if you use iTerm2
#10I never understood why outputting unescaped data is viewed differently from generating unenclosed html. Like why doesn't `println` in a modern language like rust auto-escape output to a terminal, and require a special `TerminalStr` to output a raw string.
Consider cat. It's short for concatenate. It concatenates the files based to it as arguments and writes them to stdout, that may or may not be redirected to a file. If it didn't pass along terminal escapes, it would fail at its job of accurate concatenation.
Now I don't mean to dismiss your idea, I do think you are on the right track. The question is just how to do this cleanly given the very entrenched assumptions that lead us where we are.