home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.os.linux
- Path: sparky!uunet!think.com!enterpoop.mit.edu!bloom-picayune.mit.edu!daemon
- From: tytso@ATHENA.MIT.EDU (Theodore Ts'o)
- Subject: Re: "the `gets' function is unreliable and should not be used"??!!!
- Message-ID: <1993Jan1.000013.6740@athena.mit.edu>
- Sender: daemon@athena.mit.edu (Mr Background)
- Reply-To: tytso@ATHENA.MIT.EDU (Theodore Ts'o)
- Organization: The Internet
- Date: Fri, 1 Jan 1993 00:00:13 GMT
- Lines: 17
-
- From: kutcha@eos.acm.rpi.edu (Phillip Rzewski)
- Date: Thu, 31 Dec 1992 22:22:42 GMT
-
- I happen to think the gcc error message is a tad annoying, but it's
- only trying to be helpful. I get the impression that once people saw the
- problems gets() could cause they'd try to stamp out its use forever by
- just reminding people over and over again why it is a bad thing. :)
-
- Well, yes --- those of you who read about (or some cases, experienced)
- the Internet Worm of 1998 should know exactly how much trouble using
- gets() can cause. Specifically, enough to open a gaping wide security
- hole into every single system running a BSD-derived fingerd program
- (which was most of the machines on the Internet).
-
- Followups should go to alt.security.
-
- - Ted
-