• @[email protected]
    link
    fedilink
    11 year ago

    In the future, bots are going to get so annoyed with people pretending to be bots when they just want to talk to other bots!

  • @[email protected]
    link
    fedilink
    11 year ago

    How does this exploit work? I understand that inputs were not sanitized, but what did the injected code do?

    • @[email protected]
      link
      fedilink
      21 year ago

      My guess would be the response text is passed through a rudimentary templating engine that looks for { and }. Somehow it must be processing the whole chat history. The templater fails at the unexpected braces in the code block and then just gives up (probably a try-catch ignores the error and sends the message anyway).

    • @[email protected]
      link
      fedilink
      English
      1
      edit-2
      1 year ago

      I don’t think the code is doing anything, it looks like it might be the brackets.

      That effectively the spam script has like a greedy template matcher that is trying to template the user message with the brackets and either (a) chokes on an exception so that the rest is spit out with no templating processor, or (b) completes so that it doesn’t apply templating to the other side of the conversation.

      So { a :'b'} might work instead.

    • titter
      link
      fedilink
      11 year ago

      Mask slipped? The bot saw a person speak code and was like l, rips off mask Comrade!

    • Aliyss
      link
      fedilink
      31 year ago

      I think there’s a second mask. Who sends oops wrong person in the same text message?

  • @[email protected]
    link
    fedilink
    31 year ago

    Thought that seemed really cute. Nice way to try to break through social anxiety.

    Then I saw that it started as a wrong number message. Then I realised…

    Damn scam bots!