【24h】

How to Open a File and Not Get Hacked

机译:如何打开文件而不是被黑客攻击

获取原文

摘要

Careless attention to opening files, often caused by problems with path traversal or shared directories, can expose applications to attacks on the file names that they use. In this paper we present criteria to determine if a path is safe from attack and how previous algorithms are not sufficient to protect against such attacks. We then describe an algorithm to safely open a file when in the presence of an attack (and how to detect the presence of such an attack), and provide a new library of file open routines that embodies our algorithm. These routines can be used as one-for-one substitutes for conventional POSIX open and fopen calls.
机译:粗心地注意打开文件,通常由路径遍历或共享目录的问题引起的,可以公开应用程序来攻击他们使用的文件名。在本文中,我们呈现标准,以确定路径是否安全攻击以及先前的算法如何不足以防止这种攻击。然后,我们描述了一种算法,在存在攻击时安全地打开文件(以及如何检测出这样的攻击的存在),并提供一个包含算法的新的文件开放例程库。这些例程可用作传统POSIX开放和船舶呼叫的一对一替代品。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号