Re: PHP File Upload Security Hole - Still No Fix?
| From: | Rasmus Lerdorf | Date: | Tue, 05 Sep 2000 15:43:17 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32199@lists.php.net to get a copy of this message | ||
> Rasmus Lerdorf <rasmus@php.net> wrote:
> > > Not with 'ls' it doesn't, no. But it means that the shell command is
> > > not
> > > receiving what you intended, i.e. a single parameter. With some shell
> > > commands this will be *important* and may well involve a security
> > > problem.
> >
> > But is it EscapeShellCmd()'s job to ensure a string is a single
> > parameter?
>
> If it isn't, whose job is it?
>
> If you want to pass an argument to a shell command, as simply as that, then
> EscapeShellCmd can't do it, and there isn't a built-in function that can.
> So, what use is EscapeShellCmd?
Well, it is exactly like your AddSlashes() argument. You think AddSlashes
should also add quotes. I don't think it should. These functions do
simple things. EscapeShellCmd escapes characters that are special to the
shell and AddSlashes escapes characters that are special to SQL.
Perhaps we should have AddSlashesAndQuotes() and EscapeShellArg(), and
that is probably a good idea, but it does not make the existing functions
useless as you like to keep saying.
-Rasmus