Re: eval use ?



In article <4402a62d.1659726@xxxxxxxxxxxxxxxxxxxxx>,
grue@xxxxxxx says...

It's much better to use FUNCALL or APPLY. In such examples EVAL is
totally uncalled for.

Wrong.

In the 3D screensaver example it also creates a
security hole of gigantic proportions by allowing it to execute
arbitrary code.

This has no sense.
.



Relevant Pages

  • Re: [Full-disclosure] Cisco IOS Shellcode Presentation
    ... what code that product should be allowed to execute. ... Hardware has bugs too. ... Arbitrary code execution isn't too hard on the XBox, for instance, even ... that constantly needs feeding, whether it is on a funny-looking ...
    (Full-Disclosure)
  • Re: /lib/ld-2.2.4.so
    ... > user doesn't have the permission to execute, it is enough to have read ... security of your system on the inability of users to run arbitrary code ... arbitrary code (from various features of ld.so, to programs like gdb, to ... I mean programs whose vulnerabilities (and features) are "mostly ...
    (Vuln-Dev)
  • Re: Where should I put my own perl command scripts ?
    ... the security hole which that provides the black hat. ... They can't read or execute anything, ... If an attacker can gain write access to a user's files they can change ... in ~/bin and get the user to execute commands using that users ...
    (comp.os.linux.misc)
  • Re: Solution: Asp.Net and Smb shares - without impersonation
    ... Don't you have to give the ASPNET account broad permissions to execute "net ... It seems like that's a pretty big security hole. ... > that exception, then the file will actually not exist, and you get this ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Why doesnt noexec work?
    ... That means the user may have no way to load and execute libraries ... The ld-linux.so file has a few ways to load libraries at the users ... arbitrary code in a way you have not thought about. ...
    (comp.os.linux.security)