HN2new | past | comments | ask | show | jobs | submitlogin

Would something like this work as a method to authenticate authentic clients?

http://www.cnn.com/TECH/computing/9908/20/aolbug.idg/index.h...



Paraphrasing the article, it would be for the server to use undefined behavior in the _authentic_ clients to determine that they were in fact authentic. In this case, a buffer overflow doesn't appear to crash the client, but lets the server know that it's talking to a legitimate client. That's quite clever.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: