Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

yep, putting user input into the message to be interpolated is asking for trouble

in C this leads to remote code execution (%n and friends)

in java (with log4j) this previously lead to remote code execution (despite being memory safe)

why am I not surprised the slop generator suggests it



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: