Quotes of the week
Quotes of the week
Posted Jun 3, 2010 12:27 UTC (Thu) by spender (guest, #23067)Parent article: Quotes of the week
The wonderfully hilarious main text before Al Viro's quote demonstrating his complete lack of understanding of the vulnerability class:
"I don't buy it. If we are concerned about the symlinks in the middle of
pathname, your checks are useless (mkdir /tmp/a, ln -s whatever /tmp/a/b,
have victim open /tmp/a/b/something). If we are not, then your checks are
in the wrong place."
"I don't buy it. If we are concerned about the symlinks in the middle of
pathname, your checks are useless (mkdir /tmp/a, ln -s whatever /tmp/a/b,
have victim open /tmp/a/b/something). If we are not, then your checks are
in the wrong place."
With thinking like this, I can't wait to see what kinds of "improvements" will be made to the code.
-Brad
