Re: How to develop a random number generation device



On Mon, 17 Sep 2007 23:15:52 +0000, Rich Grise wrote:

E.g. consider a program being run on a web server to process form
input from a web page. If the program suffers from a buffer overrun flaw,
simply sending the right data in a POST request can allow the attacker to
execute arbitrary code on the web server.

My God! You've got to quit using MICRO$~1 web servers!

Windows vs Linux doesn't come into it:

http://www.google.com/search?q=apache%20%22buffer%20overflow%22

C is C, whichever OS you run the program on.

Beyond that, the fact that the web is based around many "small"
transactions means that there is a significant performance gain to be had
from putting everything in one process (e.g. mod_php rather than spawning
an interpreter for each request), thereby eliminating process boundaries
which would otherwise provide some protection.

.



Relevant Pages

  • Re: Page Cannot Be Displayed
    ... Programs that use Wininet functions to post data (such as a user name or a ... password) to a Web server retry the POST request with a blank header if the ... Web server closes the initial connection request. ... >> AdAware, CWShedder and Hijackthis, to no avail. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: 6.0.28000.1106 - "Content-Length" of "0" problems
    ... Wininet retries POST requests with a blank header ... password) to a Web server retry the POST request with a blank header if the ... Web server closes the initial connection request. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: HTTP POST, Authorization header automatically sent -- WHY?!
    ... Programs that use Wininet functions to post data (such as a user name or a ... password) to a Web server retry the POST request with a blank header if the ... Web server closes the initial connection request. ... >>> unprotected resources). ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: "Invalid syntax error" on passworded sites...
    ... Programs that use Wininet functions to post data (such as a user name or a ... password) to a Web server retry the POST request with a blank header if the ... Web server closes the initial connection request. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Security Patch @832894 for Internet Explorer.
    ... Programs that use Wininet functions to post data (such as a user name or a ... password) to a Web server retry the POST request with a blank header if the ... Web server closes the initial connection request. ... The only way to be able to navigate or get email ...
    (microsoft.public.windows.inetexplorer.ie6.browser)