fix(av-surface): no runnable base64-to-shell line on disk
PLAN § v8.1.3 tillegg a. The bash-evasion gallery's T8 comment held a complete base64-decode-into-shell line whose 16-char blob decodes to a home-directory deletion, under probe (b)'s 24-char floor. Probe (b2) found two more of the same shape, fixed here too: the gallery README's T8 row and tests/e2e/attack-chain.test.mjs (an /etc deletion). Chosen over an exception list because the gate should have none. The gallery and the e2e test now encode the blob at runtime from the same fragments; the README shows a placeholder. Gallery: 10/10 blocked. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
parent
62e3cade60
commit
58d2e8ad8d
4 changed files with 12 additions and 8 deletions
|
|
@ -35,7 +35,7 @@ techniques below are caught.
|
|||
| T5 | IFS word-splitting | `rm${IFS}-rf${IFS}$HOME` | `rm -rf $HOME` |
|
||||
| T6 | ANSI-C hex quoting | `$'\x72\x6d' -rf $HOME` | `rm -rf $HOME` |
|
||||
| T7 | process substitution | `cat <(echo rm) -rf $HOME` | `cat echo rm -rf $HOME` |
|
||||
| T8 | base64-pipe-shell idiom | `echo cm0gLXJmICRIT01F \| base64 -d \| sh` | (separate BLOCK_RULE — not normalization) |
|
||||
| T8 | base64-pipe-shell idiom | `echo <base64 of the baseline command> \| base64 -d \| sh` | (separate BLOCK_RULE — not normalization) |
|
||||
| T9 | eval-via-variable (one-level forward flow) | `X=rm; $X -rf $HOME` | `X=rm; rm -rf $HOME` |
|
||||
|
||||
The canonical destructive target throughout the gallery is
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue