4 ms·
Microsoft has a number of dangerous c functions that are on the Secure Development Lifecycle "banned" list. And yes, strncpy is one of them. Some insights here
by useerup 11y ago
Microsoft has a number of dangerous c functions that are on the Secure Development Lifecycle "banned" list. And yes, strncpy is one of them.
Some insights here: https://msdn.microsoft.com/en-us/library/bb288454.aspx https://msdn.microsoft.com/en-us/library/bb288454.aspx
strncpy example vulnerability experience linked to from that article "Buffer Overflow in Apache 1.3.xx fixed on Bugtraq - the evils of strncpy and strncat!": http://blogs.msdn.com/b/michael_howard/archive/2004/10/29/249713.aspx http://blogs.msdn.com/b/michael_howard/archive/2004/10/29/24...
Source code for MS products are automatically (since SDL) screened for use of the banned functions. You'll have to use the "safer" alternatives.
- deleted 11y ago[deleted]