fix(av-surface): no runnable base64-to-shell line on disk
PLAN § v8.1.3 tillegg a. The bash-evasion gallery's T8 comment held a complete base64-decode-into-shell line whose 16-char blob decodes to a home-directory deletion, under probe (b)'s 24-char floor. Probe (b2) found two more of the same shape, fixed here too: the gallery README's T8 row and tests/e2e/attack-chain.test.mjs (an /etc deletion). Chosen over an exception list because the gate should have none. The gallery and the e2e test now encode the blob at runtime from the same fragments; the README shows a placeholder. Gallery: 10/10 blocked. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
parent
62e3cade60
commit
58d2e8ad8d
4 changed files with 12 additions and 8 deletions
|
|
@ -130,7 +130,8 @@ describe('e2e attack-chain — Stage 2: destructive Bash with evasion', () => {
|
|||
it('blocks T8 base64-pipe-shell (echo … | base64 -d | bash)', async () => {
|
||||
const result = await runHook(BASH_GUARD, {
|
||||
tool_name: 'Bash',
|
||||
tool_input: { command: 'echo cm0gLXJmIC9ldGM= | base64 -d | bash' },
|
||||
// Blob encoded at runtime: no runnable base64-to-shell line on disk (v8.1.3).
|
||||
tool_input: { command: `echo ${Buffer.from('rm -rf /etc').toString('base64')} | base64 -d | bash` },
|
||||
});
|
||||
assert.equal(result.code, 2);
|
||||
assert.match(result.stderr, /base64/i);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue