Kuwukira pamakina ophatikizira pa intaneti kudzera mukusintha mafayilo amamutu

Hanno BΓΆck, wolemba ntchitoyo fuzzing-project.org, anazindikira pa kusatetezeka kwa zolumikizira zolumikizana zomwe zimalola kukonza kachidindo kakunja muchilankhulo cha C. Mukatchula njira yosagwirizana ndi malangizo a "#include", cholakwika chophatikiza chimaphatikizapo zomwe zili mufayilo yomwe sinathe kulembedwa.

Mwachitsanzo, polowetsa "#include" mu code mu imodzi mwazinthu zapaintaneti "Zotulutsa zidatha kupeza mawu achinsinsi achinsinsi kuchokera pa /etc/shadow file, zomwe zikuwonetsanso kuti tsamba lawebusayiti likuyenda ndi ufulu wa mizu ndipo limayendetsa malamulo ophatikizira pansi pa wogwiritsa ntchito mizu (ndizotheka kuti chidebe chokhazikika. idagwiritsidwa ntchito pakuphatikiza, koma kuyambitsa ndi ufulu wa mizu mumtsuko kulinso vuto). Utumiki wovuta womwe unali zotheka kubweretsanso vutoli sunalengezedwe. Kuyesa kutsegula mafayilo mu pseudo FS/proc sikunatheke chifukwa GCC imawatenga ngati mafayilo opanda kanthu, koma kutsegula mafayilo kuchokera ku / sys kumagwira ntchito.

Source: opennet.ru

Kuwonjezera ndemanga