Hacker News new | past | comments | ask | show | jobs | submit login

I think it's easier to just avoid exec() altogether...



Sadly, there's cases where exec() is impossible to avoid - for example, every kind of tool that doesn't have a proper library and language bindings. See git and the grit library for an example.


True, but there is a lot of software out there where people don't do that. Might be interesting to find vulnerabilities that are slightly less obvious.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: