‹ BackHN Continuity

Thread

Data-only attacks are easier than you think (2024)

102 points · 45 comments · segfaultbuserr

  1. miellaby · · focus · HN ↗
    > Data-only attacks, those that do not affect a program’s control flow, have long been considered too sophisticated and niche to pose a practical threat.

    Leveraging user data to get malicious behavior is the basis of interpreter eval injection (php, js, perl, shell calls, SQL ...). These attacks are like 50 years old. What do I miss?

    1. saagarjha · · focus · HN ↗
      Most languages do not provide direct eval.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.