3 ms·
Sure, most people don't review all the code that they pull. But if you are in a position to insert "garbage data" into a commit in preparation for an attack, i
by ProblemFactory 10y ago
Sure, most people don't review all the code that they pull.
But if you are in a position to insert "garbage data" into a commit in preparation for an attack, it will be much easier to insert malicious but safe-looking code in the first place. Omit an array bounds check, disable SSL certificate validation, or anything else that looks like a mistake but will allow you to compromise the running code later.