4 ms·
>Rust didn't protect me from that, and those are the kind of vulnerabilities that we'll continue seeing regardless of language I'm still thinking about how we
by selfmodruntime 4y ago
>Rust didn't protect me from that, and those are the kind of vulnerabilities that we'll continue seeing regardless of language
I'm still thinking about how we could integrate something like that in a language or the languages package manager. I'm unsure if it's possible.
- estebank 4y agoThe only things I can think of is the use of newtypes around PathBuf that enforces things like expansion and that makes the check for you when restricting tk a specific directory. Now that I'm writing this out, this feels like it could be a very useful small crate or addition to Camino. Thank you for making me think further about this. Of course, the impl would have an associated runtime cost for the check and a more involved API surface because it's asking the developer for more information. But once you do that you can have an TryInto<PathBuf> impl to pass it to any standard method.
- manbart 4y agoHow about in the OS? This sounds like exactly the type of thin SELinux is meant to handle
- insanitybit 4y agoYeah, I think the thing is... path traversal is pretty trivial to solve. If you have a single tenancy app and you just don't want the service accessing shit it shouldn't just throw it in docker. If you have a multi-tenancy app just put every user behind a uuid.
- fiedzia 4y agoIt's possible and easy (have types for path coming from untrusted source), but it's a matter of a standard library rather than a language.
- stonemetal12 4y agoIn C++\Java this would be solved by a static analysis tool. For example Fortify covers this error.