RE: Buffer overflow examples 07-21-2014, 06:22 AM
#9
(07-21-2014, 05:59 AM)w00t Wrote: Yes it does, using strncpy, which is 2-6 more keystrokes, prevents that from happening, ever.
My point still stands, just because there's the possibility of it being vulnerable doesn't make it a bad function. Yes there are alternatives that can and probably should be used, but if you choose to use strcpy(), then it's the programmer's ignorance that determines whether it's vulnerable or not, and/or unknowing.
There is still absolutely no reason to grab some third party library just because strcpy() doesn't check the size.
Btw, functions like strncpy() don't guarantee null-termination. People use those functions because they are safer, but not many realize this, and thus might end up forgetting to set '\0' within the string. Non-terminated strings are still bad, because it would result in an overrun. The way strncpy() works, it was really probably designed for inserting characters within a string, but it had been re-identified by programmers to be used for strings all the time, just because it's safer. If you don't understand that the null terminator is implicitly NOT put anywhere in the buffer by this function, then I see it as just as much work as checking the length with using strcpy() quite honestly, although strcpy() guarantees the null terminator.
Functions are not bad, for a programmer to blame a function is ignorance. Nobody else is writing the code for you.



![[+]](https://sinister.li/images/modern/collapse_collapsed.png)