Rendered at 12:55:56 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
xx_ns 4 hours ago [-]
Very good write up! Kudos.
I recently wrote about an RCE exploit in the game Project Zomboid (which uses Lua for mods), which also used loadstring as an initial entry point for the exploit chain, but since the Lua interpreter was fully Java, byte-code memory manipulation shenanigans were out of the question for me and I had to pivot in a more traditional way.
The fact that loadstring can also load straight up bytecode was news to me though, that's interesting to know.
Natfan 3 hours ago [-]
any further information on this PZ RCE? as a casual player i'm somewhat interested -- did the vulnerability get patched?
They were very fast to patch it. The patch actually removed loadstring (among the other fixes), which broke a bunch of mods for a while. The vulns themselves could also theoretically be abused by malicious mods, which unfortunately seems to be more commonplace these days.
rurban 7 hours ago [-]
Oh oh, unsafe eval in a sandbox! (loadstring).
In my lua-like sandbox I disabled all escape hatches and unsafe functions physically by #ifndef SANDBOX. No IO, no FFI, no byte code loading, no memory funcs and such.
I recently wrote about an RCE exploit in the game Project Zomboid (which uses Lua for mods), which also used loadstring as an initial entry point for the exploit chain, but since the Lua interpreter was fully Java, byte-code memory manipulation shenanigans were out of the question for me and I had to pivot in a more traditional way.
The fact that loadstring can also load straight up bytecode was news to me though, that's interesting to know.
e: https://blog.nns.ee/2026/08/26/project-zomboid-vulns/
They were very fast to patch it. The patch actually removed loadstring (among the other fixes), which broke a bunch of mods for a while. The vulns themselves could also theoretically be abused by malicious mods, which unfortunately seems to be more commonplace these days.
In my lua-like sandbox I disabled all escape hatches and unsafe functions physically by #ifndef SANDBOX. No IO, no FFI, no byte code loading, no memory funcs and such.