Ukuhlaselwa kwezinhlelo zokuhlanganisa eziku-inthanethi ngokukhohlisa amafayela anhlokweni

U-Hanno BΓΆck, umbhali wale phrojekthi fuzzing-project.org, uqaphele ebungozini bezokuxhumana ezihlanganisayo ezivumela ukucutshungulwa kwekhodi yangaphandle ngolimi C. Lapho ucacisa indlela engafanele kusiqondiso esithi "#faka", iphutha lokuhlanganiswa lihlanganisa okuqukethwe kwefayela elingakwazi ukuhlanganiswa.

Isibonelo, ngokufaka esikhundleni esithi β€œ#faka ” kukhodi kwenye yezinsiza eziku-inthanethi, okukhiphayo ukwazile ukuthola igama elifushane lephasiwedi yomsebenzisi wempande kufayela /etc/shadow, eliphinde libonise ukuthi isevisi yewebhu isebenza ngamalungelo ezimpande futhi isebenzisa imiyalo yokuhlanganisa njengempande (kungenzeka ukuthi isiqukathi esingasodwa sisetshenziswe ngesikhathi sokuhlanganiswa, kodwa ukusebenza njengempande esitsheni nakho kuyinkinga). Isevisi eyinkinga okwakwazi ukukhiqiza kabusha inkinga ayikakhangiswa. Imizamo yokuvula amafayela ku-pseudo FS/proc ayiphumelelanga ngoba i-GCC iwathatha njengamafayela angenalutho, kodwa ukuvula amafayela kusuka ku-/sys kuyasebenza.

Source: opennet.ru

Engeza amazwana