Incorrect objects: Using the address, it is possible to check that methods are being invoked on the desired object by matching to the address on the constructor call for that object.
错误对象:使用地址,通过与对象的构建函数调用的地址进行比对,可以检查出是不是在正确的对象上调用方法。
For example, if you call on a DNS resolver to get information (such as the canonical name of an IP address), remember that this data might be directly provided by an attacker.
例如,如果您调用了一个DNS解析程序来获得一些信息(例如ip地址所对应的域名),就请记住这些数据可能会是由攻击者直接提供的。
The program text and data segments now need to get written into the mem file, either using the write system call, or by mapping the file into the process address space.
程序的文本和数据段现在需要写入到mem文件中,这可以使用write系统调用,或者通过将该文件映射到该进程的地址空间中实现。
应用推荐