New (but really - old) Windows .lnk vulnerability

  1. Virus Guy

    Dustin Guest

    I still blame lazy programmers for that. Seriously, how much more time
    does it take a person to write the code to verify the buffer has enough
    room for the string; and to invalidate bad configuration data? :(
    Dustin, Jul 26, 2010
  2. All true. I remember writing input validation subroutines, seems the
    higher level programming languages allow sloppy programming while
    freeing the programmer from the mundane chores of optimizing code.

    Anyway, my only reason for the comparison was in how long resulting
    'vulnerabilities' existed before being disclosed, not whether or not
    they were lazy programming errors or forgotten filetype backward
    compatibility functionality.
    FromTheRafters, Jul 26, 2010
  3. Virus Guy

    Dustin Guest

    Good points... and well taken here.
    Dustin, Jul 26, 2010
