3 ms·
This is pure speculation, but they may have changed it to foo==false. In C a boolean is just a byte which conventionally has the values 0 or 1, but an attacker
by muricula 6y ago
This is pure speculation, but they may have changed it to foo==false. In C a boolean is just a byte which conventionally has the values 0 or 1, but an attacker which controls a boolean can give it the value of 2, and 2!=true and 2!=false. This has lead to real exploits:
https://windows-internals.com/exploiting-a-simple-vulnerability-in-35-easy-steps-or-less/ https://windows-internals.com/exploiting-a-simple-vulnerabil...
When writing C or C++, never compare against true.
- HeyLaughingBoy 6y agoI'm not sure that's right. Too lazy to look it up right now, but my recollection is that in C, 0 is False and anything else is True.
- stonemetal12 6y agoif 47 evaluates the true branch. So in that sense you are correct, however standard C99 (the above mentioned bug uses win32's TRUE which is defined the same way) does #define true 1 therefore 47==true is false, even if 47 is true when evaluated. int a = 47; if a is true if a == true is false if a == false is false int b; b = a == true; b = 0 b = a != true; b = 1 b = a == false; b = 0 b = a != false; b = 1
- closeparen 6y agoNonzero values are truthy. You can use them bare in predicates. But they are not "== true."