Beefy Boxes and Bandwidth Generously Provided by pair Networks
Pathologically Eclectic Rubbish Lister
 
PerlMonks  

Re^2: Greetings and salutations | sudo

by zentara (Archbishop)
on Feb 07, 2020 at 19:20 UTC ( [id://11112579]=note: print w/replies, xml ) Need Help??


in reply to Re: Greetings and salutations | sudo
in thread Greetings and salutations | sudo

Thank you bliako, nice answer. I was thinking along the lines of using Perl to check the input length of the entry data, and reject it if it is longer than X many bytes.

I'm not really a human, but I play one on earth. ..... an animated JAPH

Replies are listed 'Best First'.
Re^3: Greetings and salutations | sudo | PerlOS
by bliako (Monsignor) on Feb 08, 2020 at 12:42 UTC

    Then you may want to keep a database of buffer overflow sizes for each of these poisoned applications. Hehe! Be prepared for lots and lots of entries ... unfortunately. This latest sudo/linux vulnerability to go unnoticed for several years plus all the promotion of sudo (virtually every single howto page for OSX/Linux will mention sudo at least 10 times. Some will even say "sudo here is not necessary but it will do no harm".) makes me very sceptical, elevates my usually high scepticality factor by an order of magnitude. Or two.

    On the other hand I present ... PerlOS - and no that's not this.

    bw, bliako

      From what I can see now, the best way to make money programming is secretly put backdoors into software, and then secretly sell the exploit to the 3 letter agencies. Sudo makes it easy. :-)

      I'm not really a human, but I play one on earth. ..... an animated JAPH
        From what I can see now, the best way to make money programming is secretly put backdoors into software, and then secretly sell the exploit to the 3 letter agencies.

        Microsoft business model since November 20, 1985

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://11112579]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others taking refuge in the Monastery: (4)
As of 2024-04-24 22:46 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found