Mailing Lists: Apple Mailing Lists
Image of Mac OS face in stamp
Re: warning at nslog
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: warning at nslog



On Sep 27, 2009, at 9:12 AM, Jos Timanta Tarigan wrote:
NSLog(absolutePath);

Others have replied w/an answer, but I wanted to pose a question...

What would happen if absolutePath just so happened to contain a %@ or %s in it somewhere?

Bad things, for sure.

The point of this is to encourage folks to consider a parameter not for the value you think it contains, but for the value it might contain...

Focusing on the former and not the latter is a great boon to those that exploit security holes. :)

b.bum

 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Xcode-users mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:

This email sent to email@hidden

References: 
 >warning at nslog (From: Jos Timanta Tarigan <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2011 Apple Inc. All rights reserved.