Jump to content
House Price Crash Forum

'shellshock': Bash Bug 'bigger Than Heartbleed' Could Undermine Security Of Millions Of Websites


interestrateripoff

Recommended Posts

0
HOLA441
  • Replies 55
  • Created
  • Last Reply
1
HOLA442
2
HOLA443
3
HOLA444
4
HOLA445

The interesting thing is that, in both cases, it wasn't so much a programming error as just a really dumb idea in the first place. No-one in their right mind would have sent a 'ping' message through SSL that contained an embedded length, because they would just be asking some idiot programmer to have a buffer overflow. Similarly, no-one in their right mind would put executable code in an environment variable, because that's ******ing stupid.

Sadly, it's the kind of thing people do when they have no clue about secure programming.

Edit: the latest USB attack is a similar issue. Of course no bad guy would ever build a USB memory stick that also claims to be a keyboard, and sends commands to your computer when you plug it in.

Link to comment
Share on other sites

5
HOLA446

The interesting thing is that, in both cases, it wasn't so much a programming error as just a really dumb idea in the first place. No-one in their right mind would have sent a 'ping' message through SSL that contained an embedded length, because they would just be asking some idiot programmer to have a buffer overflow. Similarly, no-one in their right mind would put executable code in an environment variable, because that's ******ing stupid.

Sadly, it's the kind of thing people do when they have no clue about secure programming.

Edit: the latest USB attack is a similar issue. Of course no bad guy would ever build a USB memory stick that also claims to be a keyboard, and sends commands to your computer when you plug it in.

automation, specially automation designed to make a device very easy to use for the dimmest of users, is usually fallible.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.




×
×
  • Create New...

Important Information