Kurwiswa kwepamhepo kuunganidza masisitimu kuburikidza nekunyengera kwemafaira emusoro

Hanno BΓΆck, munyori wepurojekiti fuzzing-project.org, akaona pamusoro pekusagadzikana kweanopindirana ekubatanidza mainterface anobvumira kugadziriswa kwekodhi yekunze mumutauro weC. Paunenge uchitsanangura nzira yekupokana mu "#include" rairo, kukanganisa kwekubatanidza kunosanganisira zviri mufaira risingakwanise kuunganidzwa.

Semuenzaniso, nekuisa "#include" mukodhi mune imwe yemasevhisi epamhepo "Zvakabuda zvakakwanisa kuwana hashi yemudzi wemushandisi password kubva pa /etc/shadow file, izvo zvinoratidzawo kuti web service iri kushanda nemidzi ine kodzero uye inofambisa mirairo yekubatanidza pasi pemudzi mushandisi (zvinogoneka kuti chigadziko chakazvimirira. yakashandiswa panguva yekuunganidza, asi kutanga nemidzi kodzero mumudziyo idambudziko zvakare). Iyo ine dambudziko sevhisi iyo yaikwanisika kuburitsa dambudziko haisati yashambadzirwa. Kuedza kuvhura mafaera mupseudo FS/proc hakuna kubudirira nekuti GCC inoatora semafaira asina chinhu, asi kuvhura mafaera kubva /sys kunoshanda.

Source: opennet.ru

Voeg