Skip to main content

Re: 感觉C语言是安全问题万恶之源

http://gengwg.blogspot.com/发信人: domini (none), 信区: Programming
标  题: Re: 感觉C语言是安全问题万恶之源
发信站: BBS 未名空间站 (Tue Apr  8 14:00:27 2014, 美东)

It is not language issue, it is the human being who made the fault. Remember
that C has to deal with all kinds of hardware, all kinds of OS, and bare
metal directly.

【 在 nod101 (exchange) 的大作中提到: 】
: 继gnutls之后, openssl也沦陷了, 原因竟然是没有做bound check
: 其实C里面也不乏做auto bound check的工具和api, 哪怕是bsd里面的strlcpy也是多少
: 能缓解overflow威胁的. 但C程序员的大多是抱着性能压倒一切的心态写代码, 不愿意
: 使用这些工具, 宁可把安全当儿戏, 连openssl这种基本的程序里也要玩火, 终于出事
: 了.
: jvm和浏览器引擎里的绝大部分安全bug也是来自于C/C++代码, 都说java不安全, 其实
: 往往是C/C++的解释器或JIT自己的问题.

Comments

Popular posts from this blog

CKA Simulator Kubernetes 1.22

  https://killer.sh Pre Setup Once you've gained access to your terminal it might be wise to spend ~1 minute to setup your environment. You could set these: alias k = kubectl                         # will already be pre-configured export do = "--dry-run=client -o yaml"     # k get pod x $do export now = "--force --grace-period 0"   # k delete pod x $now Vim To make vim use 2 spaces for a tab edit ~/.vimrc to contain: set tabstop=2 set expandtab set shiftwidth=2 More setup suggestions are in the tips section .     Question 1 | Contexts Task weight: 1%   You have access to multiple clusters from your main terminal through kubectl contexts. Write all those context names into /opt/course/1/contexts . Next write a command to display the current context into /opt/course/1/context_default_kubectl.sh , the command should use kubectl . Finally write a second command doing the same thing into ...

OWASP Top 10 Threats and Mitigations Exam - Single Select

Last updated 4 Aug 11 Course Title: OWASP Top 10 Threats and Mitigation Exam Questions - Single Select 1) Which of the following consequences is most likely to occur due to an injection attack? Spoofing Cross-site request forgery Denial of service   Correct Insecure direct object references 2) Your application is created using a language that does not support a clear distinction between code and data. Which vulnerability is most likely to occur in your application? Injection   Correct Insecure direct object references Failure to restrict URL access Insufficient transport layer protection 3) Which of the following scenarios is most likely to cause an injection attack? Unvalidated input is embedded in an instruction stream.   Correct Unvalidated input can be distinguished from valid instructions. A Web application does not validate a client’s access to a resource. A Web action performs an operation on behalf of the user without checkin...