Does this look fishy to anyone else? 06-11-2015, 02:27 AM
#1
I got an offer from Square for being < 1000 on CodeEval, the code I was given is below, and the only instruction was "fill in the vulns". It looks like a *nix-based kind of thing, so can anyone tell me if this is at all sketch? (I went ahead and refactored it)
Code:
# This program encrypts and decrypts messages at the command line.
# It runs setuid root, so that it can be used by users without giving
# them access to the (root-owned) secret encryption key.
require 'openssl'
SECRET_KEY="/etc/secrypt.key"
OUTPUT_FILE="/tmp/secrypt.out"
cipher = OpenSSL::Cipher::Cipher.new('aes-256-ecb')
case ARGV.shift
when 'encrypt'
cipher.encrypt
when 'decrypt'
cipher.decrypt
else
puts "Usage:"
puts "$0 [encrypt|decrypt] "
exit 1
end
cipher.key=(File.read(SECRET_KEY))
input = File.open(ARGV.shift)
output = File.open(OUTPUT_FILE, "w")
input.each_line { |l| output.write(cipher << l) }It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.
don't have much in the first place, who feel the new currents and ride them the farthest.
















![[+]](https://sinister.li/images/modern/collapse_collapsed.png)






