Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.computer.security > #6303
| From | Jan Panteltje <alien@comet.invalid> |
|---|---|
| Newsgroups | sci.crypt, alt.computer.security |
| Subject | Re: ? Unsafe terminal escape sequences and ANSI codes from decryption |
| Date | 2023-03-06 06:25 +0000 |
| Message-ID | <tu41fs$1lnsj$1@solani.org> (permalink) |
| References | <tu1ml1$ti6$1@news.cyber23.de> <tu3qvf$n907$1@news.xmission.com> |
Cross-posted to 2 groups.
On a sunny day (Mon, 6 Mar 2023 04:42:23 -0000 (UTC)) it happened legalize+jeeves@mail.xmission.com (Richard) wrote in <tu3qvf$n907$1@news.xmission.com>: >[Please do not mail me a copy of your followup] > >"G.K." <g@k.invalid> spake the secret code ><tu1ml1$ti6$1@news.cyber23.de> thusly: > >>Is there potential for malicious escape sequences in the plaintext? > >For a hardware terminal it is doubtful. The most they could do is >request the contents of the screen be sent to the host or auxiliary >port and not every terminal supports sending screen contents back to >the host. > >For a terminal *emulator* it's always possible that they could >identify a vulnerability in the ESC processing code that could lead to >a buffer overflow and the ability to inject bytes into the stack or >heap. > >>Where would I find timely information on such escape sequences and >>mitigating any problems they could cause or safely filtering them? > >Software vulnerabilities in the emulator would have to be found by >analyzing the source code (or binary code) of the emulator. It's not >intrinsic to the ESC sequences themselves. > >>What tools are there to filter out such sequences to ensure safely >>catting in a terminal? Are there any relevant tools in the GNU coreutils? > >None AFAIK. Maybe use hexedit cat <whatever> > test hexedit test should show any funny things And you can then use it to delete things. Now use the cleaned file 'test' hexedit is cool. :-)
Back to alt.computer.security | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
? Unsafe terminal escape sequences and ANSI codes from decryption "G.K." <g@k.invalid> - 2023-03-05 03:19 -0600
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption Grant Taylor <gtaylor@tnetconsulting.net> - 2023-03-05 09:59 -0700
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption legalize+jeeves@mail.xmission.com (Richard) - 2023-03-06 04:42 +0000
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption Jan Panteltje <alien@comet.invalid> - 2023-03-06 06:25 +0000
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption "G.K." <g@k.invalid> - 2023-03-06 01:25 -0600
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption "G.K." <g@k.invalid> - 2023-03-06 01:31 -0600
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption Simon Tatham <anakin@pobox.com> - 2023-03-06 09:29 +0000
[solved] Unsafe terminal escape sequences and ANSI codes from decryption "G.K." <g@k.invalid> - 2023-03-06 04:04 -0600
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption Phil Carmody <pc+usenet@asdf.org> - 2023-03-07 09:36 +0200
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption legalize+jeeves@mail.xmission.com (Richard) - 2023-03-06 18:36 +0000
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption drb@ihatespam.msu.edu (Dennis Boone) - 2023-03-06 22:29 +0000
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption Grant Taylor <gtaylor@tnetconsulting.net> - 2023-03-06 17:21 -0700
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption drb@ihatespam.msu.edu (Dennis Boone) - 2023-03-07 00:35 +0000
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption Grant Taylor <gtaylor@tnetconsulting.net> - 2023-03-06 18:19 -0700
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption drb@ihatespam.msu.edu (Dennis Boone) - 2023-03-07 01:41 +0000
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption Grant Taylor <gtaylor@tnetconsulting.net> - 2023-03-06 23:35 -0700
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption Jakob Bohm <jb-usenet@wisemo.com.invalid> - 2023-03-17 14:23 +0100
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption kludge@panix.com (Scott Dorsey) - 2023-03-07 02:22 +0000
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption Grant Taylor <gtaylor@tnetconsulting.net> - 2023-03-06 23:46 -0700
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption kludge@panix.com (Scott Dorsey) - 2023-03-08 20:56 +0000
Re: ? Unsafe terminal escape sequences and ANSI codes from decryption legalize+jeeves@mail.xmission.com (Richard) - 2023-03-07 05:37 +0000
csiph-web