Re: Bug #3519: EscapeShellCmd is never useful

From: Date: Thu, 17 Feb 2000 18:01:55 +0000
Subject: Re: Bug #3519: EscapeShellCmd is never useful
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-15648@lists.php.net to get a copy of this message
Well, I do see what you mean, but it is just a different way of looking at it. EscapeShellCmd() was designed to clean up user input. For example: Say you want a user to enter a month number to feed to cal. You would do: $month="2;ls"; /* user trying to be tricky */ $a=EscapeShellCmd($month); system("cal 2000 $a"); Without the escape, this simple little exploit would work, with it, it doesn't. So I am not sure how you can say that the function is never useful. If you want users to be allowed to enter spaces and other chars and have it be treated as a single arg you could do: system("cal 2000 '$a'"); -Rasmus On Thu, 17 Feb 2000, Jon Ribbens wrote: > Rasmus Lerdorf <rasmus@php.net> wrote: > > What are you talking about? EscapeShellCmd() escapes *all* the problem > > characters. Yours only escapes one. Apart from that they do the same > > thing. > > No they don't. My version escapes all characters perfectly well. > Within single quotes, no characters need escaping except single quotes. > > The difference is that EscapeShellCmd is designed to be called on an > entire string to be passed to the shell, which is no use to anyone, > since it means it has no way of telling which shell meta-characters > you really want, and which ones are evil. > > My new suggested function is designed to be called on a single argument > to a shell command line, and causes that single argument to be definitely > interepreted as a single argument to a command, and nothing else. > > As an example, if you use the existing EscapeShellCmd function on a string, > and the user-supplied input has a space character in it, then you end up > with the user-supplied input being parsed as two arguments instead of one. > > See my example in the bug report for an example of the correct way to > pass user input to a shell command line. > > Cheers > > > Jon > -- > \/ Jon Ribbens / jon@oaktree.co.uk >

« previous php.dev (#15648) next »