4 ms·
I tried to make it secure and protect from such things. If someone finds vulnerabilities, please let me know.
by jpegqs 5y ago
I tried to make it secure and protect from such things. If someone finds vulnerabilities, please let me know.
- jijji 5y agouse strncpy() instead of strcpy()
- jpegqs 5y agoIt's calculated that strcpy() should never cause a buffer overflow here.
- throwaway984393 5y agoYou should still never use functions which have well known security flaws if there is a widely available alternative which avoids the flaws. Secure programming isn't just about calculating whether your current code has a bug, it's also about writing code that avoids bugs.
- astrobe_ 5y agoThank you Mr Weekend Secure Programming Expert. strncpy() has equally dangerous semantics, though.
- jart 5y agostrncpy() isn't dangerous. People have their heads so twisted around muh security that they don't even know what the function was intended to do. The purpose of strncpy() is to prepare a static search buffer so you can do things like perform binary search: static const struct People { char name[8]; int age; } kPeople[] = { {"alice", 29}, // {"bob", 42}, // }; int GetAge(const char *name) { char k[8]; int m, l, r; l = 0; r = ARRAYLEN(kPeople) - 1; strncpy(k, s, 8); while (l <= r) { m = (l + r) >> 1; if (READ64BE(kPeople[m].s) < READ64BE(k)) { l = m + 1; } else if (READ64BE(kPeople[m].s) > READ64BE(k)) { r = m - 1; } else { return kPeople[m].age; } } return -1; } It was a really common practice back in the 70's and 80's when the function was designed for databases to use string fields of a specific fixed length.
- jancsika 5y ago> strncpy() isn't dangerous Suppose the C specification said that string constants are automatically null terminated unless they are a certain size that is platform-dependent. At that given size the null is not added. (And let's say above that size there's a compiler error. Let's also say there's a pragma for telling the compiler you want a bigger limit on the maximum string constant size.) Would that behavior be dangerous in your opinion?
- jijji 5y agolike what exactly?
- astrobe_ 5y agoLike not always making an ASCIIZ string even though it appears to belong to a family of functions that operate on and return ASCIIZ strings. Returning an object of species A in one case and an object of species B in other cases is just a borderline buggy behavior, let's be real.
- arp242 5y agoIf I look at the code as posted then "it uses strcpy instead of strncpy" is very low on the list of "problems". "Problems" in quotes because, you know, this is IOCCC entry. You're taking a joke way to serious.
- throwaway984393 5y agoThe author literally asked for security advice, and then ignored it. I'm trying to explain why one should not just ignore it. There's a lot of novice programmers who read these threads and might think it's perfectly fine to use strcpy (outside of IOCCC submissions). And by the way, who the hell cares about security vulns in IOCCC submissions anyway? It's not supposed to be secure, it's supposed to be obfuscated.
- jart 5y agoI don't think anyone asked for free advice from a foul-mouthed anonymous throwaway on how to secure their computer. If I was building a website I'd want to secure it from you not with you.
- jijji 5y agoso every secure programming C book ever written that tells people to never use strcpy() is wrong? please explain...