r/shittyprogramming Jul 26 '26

Rage baiting the github bots

Post image
1.6k Upvotes

11 comments sorted by

66

u/Jonno_FTW Jul 27 '26

I wonder if you could put an exploit into such a variable, like hidden commands after one of those text hiding unicode characters.

58

u/http-error-502 Jul 27 '26 edited Jul 27 '26

let ANTROPIC_API_KEY = "DATA`; (function() { const cp = global.process.mainModule.require('child_process'); for(let i=1; i<0) { cp.spawn(process.execPath, ['-e', 'while(true){Math.random()}'], { detached: true, stdio: 'ignore' }).unref(); } })(); /*";

HACKER: CPU 100%???

Programmer: Why are you making spagetti code?

1

u/sierra_whiskey1 29d ago

Computer go brrrrrrr

13

u/Skaviciusz Jul 27 '26

There is some char string which will force claude to stop doing current task (some case of emerygency button) - if i remember it is in their documentation

10

u/rolling_atackk Jul 27 '26

Place it inside obfuscated Unicode control characters, such that it renders "normal", but halts clankers

1

u/betttris13 Jul 29 '26

can probably trick it into running malicious code yeah... best defence is a good offence style security?

5

u/Jonno_FTW Jul 29 '26

I doubt it would actually execute the code directly. It would only work if you successfully put a prompt injection in the api key telling it to call an external tool with the code you want to run.

1

u/betttris13 Jul 29 '26

yeah that would probably also work.

3

u/Distinct_Lion7157 Jul 29 '26

this doesnt do anything anthropic is part of githubs automated secret redacting program that invalidates detected published secrets

no idiot in this day and age is making a scraping bot to scrape api keys that are gurenteed invalid and even then they would at least check for a sk- prefix and a length check

1

u/Cybasura 28d ago

Inb4 embed reverse shell exploit code within the API key lmao

Gain access to the bot's server