3 ms·
A colleague had this to say: I remember a spate of answerback hacks with vt100s. the remote host could program the message by sending an escape sequence, and t
by binarycrusader 9y ago
A colleague had this to say:
I remember a spate of answerback hacks with vt100s. the remote host could program the message by sending an escape sequence, and then get the vt100 to type the string back. you could make the tty execute commands that would give the attacker privs, and stuff like that. The main fix was hardening mail clients to filter escape sequences; simpler days to be sure, but the basic flaw (non-filtered text) still occurs in html forms