3 ms·
Doesn't this get into the issue of whether XML dependency injection is a good idea? All of the wiring and some logic is built up in some files that are outside
by typicalrunt 14y ago
Doesn't this get into the issue of whether XML dependency injection is a good idea? All of the wiring and some logic is built up in some files that are outside of the build/compilation process. Doing "proper dependency injection" (quotes for sarcasm) to me has always made me worry that I've lost control of how my application works, and somehow based on the right XML/JSON/etc config magic it will work perfectly and meet all security standards.
Maybe I'm just too jaded...
- jerf 14y agoDo your remote users have any control over those files? Probably not, or at least, probably not on purpose. The problem here is highly extensible systems that consume some user-sourced data and ultimately contain some sort of path whereby the user is essentially running a program with some set of capabilities they are not supposed to have. (Many of these attacks have resulted in arbitrary code execution, but weaker forms are possible, where perhaps you can only instantiate a class that results in some file being created on disk with arbitrary contents, or reads from it, or something.) Many of these systems are written with the use case in the developer's mind where the data can be trusted to some degree, because perhaps they assume it's going to be read only by the program that generated it and only viewed by the user who already owns the computer, etc. In some sense the error only occurs when one takes this sort of software and then exposes it to the network, but it can be hard to realize when you... or somebody buried three layers deep in $YOUR_FAVORITE_FRAMEWORK... has done that.
- ihsw 14y agoDependency injection and mass assignment/run-time execution of new code are two separate issues. Although both are convenience niceties, the latter is based on user input while the former is not.