hydroptic ,

While the network service is designed to only accept commands that start with “wl” or “nvram get,” ONEKEY found that the restriction could be trivially bypassed by injecting a command after shell meta-characters like ; , & , or, | (e.g., “wl;id;”).

Whenever I feel like I'm a terrible programmer, I remind myself that there are vast amounts of confident coders out there being paid for code with idiotic mistakes like this and they have no intention of getting any better at it

  • All
  • Subscribed
  • Moderated
  • Favorites
  • [email protected]
  • kbinchat
  • All magazines