Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: ShadowAce

Not clear to me what this can do. The string literal is read and has BiDi control characters. Will it just change the direction of how the characters are displayed in the browser or other software? Does the BiDi code keep reading until it finds another control character, thus causing a buffer read overrun enabling a buffer exploit?


3 posted on 11/01/2021 11:18:42 AM PDT by pierrem15 ("Massacrez-les, car le seigneur connait les siens" )
[ Post Reply | Private Reply | To 1 | View Replies ]


To: pierrem15
Not clear to me what this can do.

That may be deliberate so black hats will have to figure it out.

5 posted on 11/01/2021 11:20:21 AM PDT by E. Pluribus Unum ("Communism is not love. Communism is a hammer which we use to crush the enemy." ― Mao Zedong)
[ Post Reply | Private Reply | To 3 | View Replies ]

To: pierrem15; E. Pluribus Unum
As E. Pluribus Unum pointed out, the description was not exactly clear. This is probably done on purpose. :)

But the scary part is it doesn't really matter what OS or software you use--it can be inserted everywhere as this is a sourcecode-level exploit that the compilers do not catch.

7 posted on 11/01/2021 11:46:13 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 3 | View Replies ]

To: pierrem15

Not too concerned about it. They have to get it into your code. If someone got to my codebase, there would be more issues than them putting something like this into it.


10 posted on 11/01/2021 11:48:27 AM PDT by pas
[ Post Reply | Private Reply | To 3 | View Replies ]

To: pierrem15

I wonder if it has to do with programming languages that allow pragmas/commands within comments, perhaps like the shebang directives in bash?

https://bash.cyberciti.biz/guide/Shebang

ANY time data (or code comments) have a chance of changing context into code execution, you have a potential security vulnerability.


17 posted on 11/02/2021 1:30:41 PM PDT by mbj
[ Post Reply | Private Reply | To 3 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson