Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <E1XcJJc-0008Hw-2U@rmm6prod02.runbox.com>
Date: Thu, 09 Oct 2014 15:23:56 -0400 (EDT)
From: "David A. Wheeler" <dwheeler@...eeler.com>
To: "oss-security" <oss-security@...ts.openwall.com>
Subject: Re: Thoughts on Shellshock and beyond

On Wed, 8 Oct 2014 21:31:37 -0700, Michal Zalewski <lcamtuf@...edump.cx> wrote:
> Sure, agreed. I don't think the code / data catchphrase accurately
> conveys this principle to developers, though =)

I've expanded the detection or prevention section of my paper in general:
  http://www.dwheeler.com/essays/shellshock.html#detect-or-prevent

In particular, I've given more information on separating code/data here,
in a way that I hope captures the point for developers:
 http://www.dwheeler.com/essays/shellshock.html#separate-code-data

--- David A. Wheeler

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.