Re: NSTask Leaking...
Re: NSTask Leaking...
- Subject: Re: NSTask Leaking...
- From: "Mr. Gecko" <email@hidden>
- Date: Thu, 29 Jan 2009 16:00:42 -0600
not if I take the parts for MD5 and place it in my own binary.
On Jan 29, 2009, at 3:19 PM, Jeremy Pereira wrote:
On 29 Jan 2009, at 19:33, Mr. Gecko wrote:
I'm just going to use sscrypto framework for it...
If a malicious person can replace an executable with his own, he can
probably also replace a framework...
Regardless of any other problems, you've introduced a serious
weakness - a hacker just needs to temporarily change /sbin/md5 to
a shell script that cats the expected output. For that matter,
they could easily edit the binary to change the string "/sbin/md5"
to another path that does the deed (to avoid having to mess with
sbin each time)
If you are trying to write secure code, don't execute external
binaries that you have no control over and expect it to be secure.
Glenn Andreas email@hidden
<http://www.gandreas.com/> wicked fun!
JSXObjC | the easy way to unite JavaScript and Objective C
_______________________________________________
Cocoa-dev mailing list (email@hidden)
Please do not post admin requests or moderator comments to the list.
Contact the moderators at cocoa-dev-admins(at)lists.apple.com
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden
_______________________________________________
Cocoa-dev mailing list (email@hidden)
Please do not post admin requests or moderator comments to the list.
Contact the moderators at cocoa-dev-admins(at)lists.apple.com
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden