a holiday gift from Robert "wormer" Morris

John B. Nagle jbn at glacier.STANFORD.EDU
Mon Nov 7 12:27:19 AEST 1988


In article <24 at jove.dec.com> vixie at decwrl.dec.com (Paul Vixie) writes:
>The bug in fingerd was a big surprise, though.  Overwriting a stack frame
>on a remote machine with executable code is One Very Neat Trick.

       Yes.  But not all that uncommon, given classical C's rather casual 
approach to array sizing.  "login" in V6 UNIX could be broken by submitting 
very long, suitably constructed passwords.

					John Nagle



More information about the Comp.unix.wizards mailing list