Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 15:43:17 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32199@lists.php.net to get a copy of this message
> Rasmus Lerdorf <rasmus@php.net> wrote: > > > Not with 'ls' it doesn't, no. But it means that the shell command is > > > not > > > receiving what you intended, i.e. a single parameter. With some shell > > > commands this will be *important* and may well involve a security > > > problem. > > > > But is it EscapeShellCmd()'s job to ensure a string is a single > > parameter? > > If it isn't, whose job is it? > > If you want to pass an argument to a shell command, as simply as that, then > EscapeShellCmd can't do it, and there isn't a built-in function that can. > So, what use is EscapeShellCmd? Well, it is exactly like your AddSlashes() argument. You think AddSlashes should also add quotes. I don't think it should. These functions do simple things. EscapeShellCmd escapes characters that are special to the shell and AddSlashes escapes characters that are special to SQL. Perhaps we should have AddSlashesAndQuotes() and EscapeShellArg(), and that is probably a good idea, but it does not make the existing functions useless as you like to keep saying. -Rasmus

« previous php.dev (#32199) next »