3 ms·
I realize this is nothing new, but these vulnerabilities are so incredibly simple (eg. Shellshock, this) and are because of obscure features no one touches (eg.
by 0942v8653 12y ago
I realize this is nothing new, but these vulnerabilities are so incredibly simple (eg. Shellshock, this) and are because of obscure features no one touches (eg. Shellshock, this). Maybe that's too much to take from the 2 things I'm thinking of at the moment—any other examples?
- marcosdumay 12y agoWell, Heartbleed is as simple and because of an as obscure feature. The only difference is that Heartbleed wasn't following the specs thus I'm not sure it would fit the same category.
- _delirium 12y agoIt does make me feel like my decision to "parse" RSS feeds using ~5 lines of Perl regex, which seemed dumb at the time, is maybe still sorta-dumb, but at least not worse than using a default XML parsing library. All I really need out of an RSS feed is to find the author, URL, date, and body, which I was just too lazy to do "properly", so used some regexes as a quick hack. But seeing what stuff "proper" XML parsers have buried in them, I think I might stick with the Perl script...
- LukeShu 12y agoShellshock wasn't because of a feature that no one used, just a feature that no one thought about. That feature is the mechanism for how functions are passed to subshells--something that happens automatically, out-of-view of the programmer, but is used frequently nonetheless.