I should find an real-world safe Rust program that has exploitable stack overflow and actually exploit it as a proof of concept.
Ah, stack overflow via recursion. That makes sense. Not that I'd really want recursive algos in security code :)
-
-
true, even if the stack probe issue is fixed, it's still a DoS (in an attack model where input is untrusted)
-
though as you well know, splitting code into security-sensitive and not doesn't tend to work well in practice
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.