3 ms·
"strings" is also vulnerable: http://lcamtuf.blogspot.com/2014/10/psa-dont-run-strings-on-untrusted-files.html http://lcamtuf.blogspot.com/2014/10/psa-dont-run-
by twinge 12y ago
"strings" is also vulnerable: http://lcamtuf.blogspot.com/2014/10/psa-dont-run-strings-on-untrusted-files.html http://lcamtuf.blogspot.com/2014/10/psa-dont-run-strings-on-...
Inspecting files is apparently hazardous.
- MichaelGG 12y agoNo, writing general handling code in C is hazardous.. And after that, mixing domains, especially for human convenience, is dangerous as parsing gets complicated and leads to the unexpected. Rust can solve the first problem. A sense of elegance or just good taste can solve the second.
- pjmlp 12y agoAny language with native code compilers can be used for 90% of the stuff C is still used, not only Rust. I think due to the rise in VM based runtimes and lost of investment in alternative languages (e.g. Modula-2....) many developers created the myth that C and C++ are the only languages with native code compilers.
- xorcist 12y agoThis problem with LESSOPEN would exist even if less was written in Rust. The same goes for the strings command.
- Scramblejams 12y agoAll the more reason to use memory safe languages as far up the stack as you can go.
- Animats 12y agoRust can solve the first problem. I sure hope so. But the language needs more mileage on it to be confident that the checking works.
- Animats 12y agoYou're right; it was "strings" last month, not "file".