Path: csiph.com!weretis.net!feeder6.news.weretis.net!i2pn.org!i2pn2.org!.POSTED!not-for-mail From: Anonymous Newsgroups: rocksolid.programming Subject: that's for interactive mode Date: Thu, 17 Dec 2020 05:05:23 -0800 Organization: def2 Message-ID: References: Content-Type: text/plain; charset=UTF-8 Injection-Info: i2pn2.org; posting-account="def2"; logging-data="14043"; mail-complaints-to="usenet@i2pn2.org" Xref: csiph.com rocksolid.programming:159 >>cef79e59c453b34000 I understand that you describe the interactive mode of Lynx, so this does not concern my setup (I use predefined calls where the hostname and everything is fixed, and the user input is used as a group or message. My concern here was that separate commands could be injected this way, but I have not managed to do this). Still good to know, thanks. A little research shows that Lynx has a pretty good track record: https://www.cvedetails.com/vulnerability-list.php?vendor_id=5836&product_id=9869&version_id=0&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=0&cweid=0&order=1&trc=5&sha=3f93be2ac58707975914133ab453aee7b2962f26 Of course somebody could probably still worm their way in, we will see :-) -- Posted on def2