Bug #18291 Updated: exec() arguments (+suggested solution)

From: Date: Sat, 20 Jul 2002 00:56:57 +0000
Subject: Bug #18291 Updated: exec() arguments (+suggested solution)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14671@lists.php.net to get a copy of this message
 ID:               18291
 Updated by:       sniper@php.net
 Reported By:      php.hc@saustrup.net
-Status:           Open
+Status:           Verified
 Bug Type:         Program Execution
 Operating System: RedHat Linux 7.3
-PHP Version:      4.1.2
+PHP Version:      4.3.0-dev
 New Comment:

Seems like safe-mode does mess up the parameters.
I'm not sure if this is actually the correct behaviour...



Previous Comments:
------------------------------------------------------------------------

[2002-07-19 20:09:28] php.hc@saustrup.net

I tried what you suggested, and this is what came out:

Script 1: "213
Script 2: 213

I'm a security freak, so I have safe_mode enabled. Apparently safe_mode
is infact the cause of this error, because when I disabled it in
php.ini, the two scripts worked like you suggested:

Script 1: 213 123
Script 2: 213

Please test this yourself and post the results.

------------------------------------------------------------------------

[2002-07-12 18:51:52] sniper@php.net

FYI: PHP uses popen(), not execve()..

In 4.2.1 there is pcntl_exec() which behaves similarly to
the system execve. Maybe that's what you want to use..?


Try these scripts:

shell_args_1arg.php:
<?php echo exec('./test.sh "213 123"'); ?>

shell_args_2arg.php:
<?php echo exec('./test.sh 213 123'); ?>

test.sh:
<----8<---->
#!/bin/sh

echo $1
<----8<---->



------------------------------------------------------------------------

[2002-07-12 08:31:07] php.hc@saustrup.net

And just to make it perfectly clear what arguments my binary is
getting:

Arg1: 1
Arg2: 2
Arg3: 3
Arg4: "a
Arg5: b
Arg6: c"
Arg7: 4
Arg8: 5
Arg9: 6

------------------------------------------------------------------------

[2002-07-12 08:28:20] php.hc@saustrup.net

As far as I can see, it's not even required by the exec()'ing user to
have a valid shell in /etc/passwd, so I very much expect that the
binary is being exec()'d directly, without the use of a shell.
If you check out the man page for the execve() function, you'll see
that arguments are actually submitted as an array, and not as a whole
string. If they were infact passed through a shell (I believe the
backticks and passthru() does this), escapeshellarg() might have been
the solution - but not in this case. I tried it, but exec() apparently
still splits up the string where it finds whitespaces (escaped or not),
and passes it on to ie. execve().

And just to make it perfectly clear what I want:

Binary: /usr/bin/binary
Arg1: 1
Arg2: 2
Arg3: 3
Arg4: a b c
Arg5: 4
Arg6: 5
Arg7: 6

------------------------------------------------------------------------

[2002-07-12 00:21:28] sniper@php.net

Not any bug. It's up to the external program how
it handles the arguments you pass it..try same on the cmd line and
you'll understand what I mean. To get "'s through, you need to escape
them..

Check this out:
http://www.php.net/manual/en/function.escapeshellarg.php

exec() doesn't split anything, it passes what is given to it
straight to the shell to be executed as is.


------------------------------------------------------------------------

The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
    http://bugs.php.net/18291

-- 
Edit this bug report at http://bugs.php.net/?id=18291&edit=1



Thread (10 messages)

« previous php.bugs (#14671) next »