Re: ? Unsafe terminal escape sequences and ANSI codes from decryption
Grant Taylor <[email protected]> Mon, 6 Mar 2023 23:35:53 -0700
| Newsgroups | sci.crypt,alt.security.pgp,alt.bbs,comp.terminals,alt.computer.security |
|---|---|
| Organization | TNet Consulting |
| Message-ID | <[email protected]> |
On 3/6/23 6:41 PM, Dennis Boone wrote: > I'm envisioning something more like some non-host party injecting > hostile text and control sequences that the host ends up sending to > some legitimate user. Hum. If I'm understanding you correctly, say someone manages to post a message to an echo -- I think that's the term I want -- that contains hostile control sequences and the terminal user reads said message, thereby causing their terminal (emulator) to interpret said hostile control sequences. I'm eliding how such hostile control sequences make it that point and only focusing on an unwitting user accidentally causing the host to send them. -- Grant. . . . unix || die