Comment 2 for bug 1507025

Revision history for this message
Seth Arnold (seth-arnold) wrote :

I can't imagine the effort involved in hardening all applications to treat the hostname as untrusted input.

ISPs that sell vservers are really no different from Intel or AMD or whoever makes your CPU -- you trust them completely and totally with your data, your executables, and your entire operating environment. They can inject anything they wish into your system's memory whenever they wish.

Making sure the dhcp clients don't allow setting these kinds of hostnames however, that might be a good idea. Enforcing the usual dns guidelines of a-zA-Z0-9-_ might be worthwhile..

Thanks