| [10-31 11:07] | [Chat] | Icewolfz: and object is not used as a genric id as well |
| [10-31 11:07] | [Chat] | Icewolfz: new is only bad due ot the creation process |
| [10-31 11:07] | [Chat] | Icewolfz: object doenst break anything |
| [10-31 11:08] | [Chat] | Icewolfz: there are very few names that break stuff |
| [10-31 11:08] | [Chat] | Icewolfz: most are banned more to prevent abuse/confusion |
| [10-31 11:09] | [Chat] | Rmp: hmm wonder if a player called sudo could be abused with finger to shell out to prompt. lol |
| [10-31 11:09] | [Chat] | Icewolfz: wont we do not have any shell outs |
| [10-31 11:09] | [Chat] | Icewolfz: so nothing directly executes anyting on shell |
| [10-31 11:09] | [Chat] | Rmp: right, but I'm thinking of possible methods to abuse |
| [10-31 11:10] | [Chat] | Rmp: possible, however difficult, to get the driver to run anything under its PID permissions. |
| [10-31 11:10] | [Chat] | Icewolfz: anything at that point would need and immortal to do it |
| [10-31 11:11] | [Chat] | Icewolfz: user space is all wrapped up |
| [10-31 11:11] | [Chat] | Icewolfz: worse case users may cause is the mud to crash as they do not have any direct access to anything |
| [10-31 11:11] | [Chat] | Icewolfz: and the crash would be more due to memory or a bug in the code |
| [10-31 11:11] | [Chat] | Rmp: I'm worried more about input validation via commands called against players who may have names that do bad things. |
| [10-31 11:12] | [Chat] | Icewolfz: but i wil lsay this is old code so god only knows what may be there |
| [10-31 11:12] | [Chat] | Icewolfz: inputvalidtion wont effect anyting |
| [10-31 11:12] | [Chat] | Icewolfz: there are multiple layers |
| [10-31 11:12] | [Chat] | Icewolfz: and nothing runs on direct os |
| [10-31 11:12] | [Chat] | Icewolfz: everything is wrapped at he mud layer in lpc code |
|
| Back to List |