On 12/3/2013 1:59 PM, Ray Overby wrote:
flawed function code validation - If you pass a negative number or a
large positive number you can control where the SVC branches to. I have
seen these types of problems "in the wild" where I was able to branch to
a private area where any code you wanted could be executed.

BTDTGTTS - long ago I "discovered" how to kill two flies with one stone - in the example, change the test to CL R1,=F'8' - after that, extraneous bits may be tested with an EX R1,

Gerhard Postpischil
Bradford, Vermont

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to