Edward Jaffe has now, inevitably and I trhink wisely, blown the gaff.

As some few of you perhaps did not already know, the prototypically C
data type of an SBCS string "of conceptually unlimited length", EOS
delimited by a nul, x'00', has been exploited over and over again to
do great mischief.

The LONGPARM-enablement flag provided by the Binder for authorized
programs that request it provides some protection against the misuse
of 32760 PARM bytes for malicious purposes.

We shall see whether it is enough protection.  I suspect that it is
not.  I could, if I wished, write a species of bootstrap loader in
much less than 32760 bytes that would read more from the PARMDD data
set; and I can think of others, regular contributors here, who could
do a better job of it.  I do not, however, have a better alternative
suggestion to make within this design framework.

John Gilmore, Ashland, MA 01721 - USA

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to