2 ms·
What's the realistic issue with code injection over HTTPS TCP parsing into expected messages? If it is an issue for your system, can't you try read into some e
by EddieJLSH 3y ago
What's the realistic issue with code injection over HTTPS TCP parsing into expected messages? If it is an issue for your system, can't you try read into some expected shape and throw an error if it doesn't parse to circumvent that?
- schemescape 3y agoI was specifically talking about Common Lisp’s print/read functions which are not safe for untrusted input: https://github.com/salewski/cl-safe-read/blob/master/README.md https://github.com/salewski/cl-safe-read/blob/master/README....