Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login

Bingo, you should never pass arbitrary strings where they could be used as format specifiers, it's like running arbitrary code. Some compilers even issue warnings when you pass non-literal format strings to the printf family.


view as:

Legal | privacy