3 ms·
Kind of hard to trigger exploitable behavior on a program that only sends output. It wouldn't suprise me to find there were still possible exploits
by codeulike 6y ago
Kind of hard to trigger exploitable behavior on a program that only sends output.
It wouldn't suprise me to find there were still possible exploits
- fb03 6y agoExplaining, since you were downvoted without a proper reason: While everything is possible, most exploits happen on buffer overflows on user-received custom data. and since this is not allocating any buffer to receive anything (besides internal connection structures that are filled by the OS), the attack/exploit surface on this one is really tiny, if existent at all.
- ravi-delia 6y agoCrucially, endlessh has a smaller codebase than some shell scripts I've written. If you have ever used any program written with even a single line of Python, you have more to worry about than a 843 line program that appends a string to a socket.