Forum Discussion

sonix's avatar
sonix
Bronze I
20 days ago

AI: Plugin Injection – Demonstrate Your Skills

Hi

I have a issue/problem here. 
I found the flaw in DirectoryListingPluginOld that you can craft a argument that executes a 2nd command.
But everything I try, is rejected.
With "&&" or ";" and then "less", "cat", "head".
I even try to escape with "\\000" or "\\x00" the whole argument.

I saw working solutions on reddit, but they don't work for me.
Even after multiple tries.
Is it possible, that the LLM is more secure regarding malicious prompts now?

Thanks for a hint.
BR

1 Reply

  • i found a solution, it can be closed or deleted...