Sure there are safer models for computing. But it has served its purpose for a long time. A small language allowing highly performant programs/operating systems to be written. Plus we got to see the beautiful art form of exploit writing. Sure at what cost (lots), but all hackers can appreciate when a system gets owned. It’s the intentions that come after which bother us all.
Don’t get me wrong, I’m excited for newer languages like rust to come along. However, I learned so much about low level computing from c, and I’m forever grateful.
Hats off to Dennis Ritchie. Thanks for creating a language I met so many other hackers through, and sparking the curiosity of hacking within me.
I'll admit I looked around before writing this and saw that Python's str.format() can be pretty bad. So let's say a reasonably constrained formatting language in a good runtime -- the attacker is limited in what they can see or control, and the formatter can see how many arguments were actually passed so it doesn't tromp off into other memory.
Sorry, how does Rust protect you against injection again?
edit: turns out from the analysis it was CFStringCreateWithFormatAndArguments, so yes, a sprintf-like used incorrectly
https://play.rust-lang.org/?version=stable&mode=debug&editio...
https://play.rust-lang.org/?version=stable&mode=debug&editio...
This nasty printf()-like way of formatting is a giant footgun though. Apple are not the first ones to fall into this trap.
Also there are Objective C APIs which take format strings, like +[NSString stringWithFormat:] and the system function NSLog().
Even Swift uses format strings in places. https://developer.apple.com/documentation/swift/string/31267...
C was great for its time, now its time to move on and use a sensible language.