3 ms·
You should never assume any method of executing any attacker controlled code is safe, unless something explicitly calls that out and also has put Google-level a
by chc4 2y ago
You should never assume any method of executing any attacker controlled code is safe, unless something explicitly calls that out and also has put Google-level amounts of effort into supporting that.
- _factor 2y agoMy interpreter only accepts print and addition to a predefined variable. Let the attackers print and count all they want. The problem isn’t the execution, it’s the scope of what it means to “execute”.
- kfmdnfj 2y agoDepending on the implementation, there might still be multiple bugs lurking, especially in input parsing
- deleted 2y ago[deleted]