Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: at the risk of another flamefest..

at the risk of another flamefest..

From: *Hobbit* <hobbit_at_avian.org>
Date: Mon, 15 Jul 1996 00:36:49 -0400

This one triggered my "old classic" filter. Your patch has

- char buf[256];
+ char *buf=alloca(strlen(name)+50);

and five lines later, the original code fragment

        for (cp = name; *cp; )
                n += *cp++;

Is this a family of mistakes that male programmers constantly make?? It's
doesn't matter how big your buffer is, it's how you USE it -- i.e. how you
limit what can be stuffed INTO it. Essentially unbounded processing of this
sort over areas that may not necessarily be conveniently zero-filled or
pre-terminated for you is one reason we have so many of these BUGS...

Maintaining perspective,

_H*
Received on Jul 15 1996

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos