oss-sec mailing list archives

Re: Thoughts on Shellshock and beyond


From: "David A. Wheeler" <dwheeler () dwheeler com>
Date: Thu, 09 Oct 2014 00:03:13 -0400

I would take a functional approach to this: is there a way an attacker could send data that would be misinterpreted as 
code? If so, could that harm anything?

It is obviously much better if the communication does not use shared resources (like the environment). But this is all 
logical - in the end all of this is in the same memory. The goal is to maximize the separation enough so that attackers 
cannot misuse it.  The better the separation, the less risk later.
 

--- David A.Wheeler

Current thread: