01:33 am, 25 Nov 03

Spot the security hole (from conjecture):
struct header {
    int cmd, id, len;


struct header hdr;
char buf[1024], ubuf[1024];
if(read(sock, &hdr, sizeof(hdr)) != sizeof(hdr))
if(hdr.len < sizeof(hdr) || hdr.len > 1024)
read(sock, buf, hdr.len);
buf[1023] = 0;
snprintf(ubuf, sizeof(ubuf), "command was %s", buf);