wdormann ,
@wdormann@infosec.exchange avatar

Reminder:
It's never been safe to run a program out of a directory that contains other untrusted files.
https://insights.sei.cmu.edu/blog/carpet-bombing-and-directory-poisoning/

https://twitter.com/WithinRafael/status/1782213111296229776

bontchev ,
@bontchev@infosec.exchange avatar

@wdormann Windows really needs a DLLPATH variable, working similar to how the Linux PATH variable works - i.e., only the directories listed there are searched for DLLs in the specified order and the current directory is not searched, unless it is explicitly listed there (which by default it ought not to be).

tuxicoman ,
@tuxicoman@social.jesuislibre.net avatar

@bontchev @wdormann

Executable bit too. In other words, solution is to not use Windows

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines