From: Mikael Brockman Date: 2004-08-28T13:20:37+09:00 Subject: Re: performance comparison David Ross writes: > Its common security knowledge gets() is unsafe. It has > no bounds checking. I only talk about security and > ease of use. Its the only thing I like to talk about. > :) > > I love security. > > from my manpages-- SECURITY CONSIDERATIONS > The gets() function cannot be used securely. Because > of its lack of > bounds checking, and the inability for the > calling program to reliably > determine the length of the next incoming line, > the use of this function > enables malicious users to arbitrarily change a > running program's func- > tionality through a buffer overflow attack. > > > --------- > > There are many other insecure function calls. The > knowledge on how to use them properly is very nice to > have. Which most people lack. Also using printf() for > certain types of usage can lead to exploits. buffer > overflow problems, etc. > > btw, I am a BSD dragon. So expect to get information > like this from me ;) > > I bite, be careful I don't see how the safety of the corresponding C functions is relevant; we were talking about the (safe) Ruby variants.