|
|
|
|
|
by franga2000
332 days ago
|
|
If you pipe your emails to bash, I can also run code by sending you an email. How is this news? You must never feed user input into a combined instruction and data stream. If the instructions and data can't be separated, that's a broken system and you need to limit its privileges to only the privileges of the user supplying the input. |
|
Well, I have some bad news about how LLMs work...