Re: Re: Pretty mammoth security issue with safe_mode_exec
| From: | Stanislav Malyshev | Date: | Mon, 08 Jan 2001 12:28:19 +0000 |
| Subject: | Re: Re: Pretty mammoth security issue with safe_mode_exec | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-43360@lists.php.net to get a copy of this message | ||
ZS>> Oh, well, actually I was too quick to respond - ".\" is indeed
ZS>> an invalid escape, but PHP treats it as ".\\", and not just ".".
ZS>>
ZS>> I just checked, shells indeed accept \.\. as if it was "..", so
ZS>> the bug is legit. If anybody attempts to fix it - note that \..
ZS>> and .\. are also possible.
From what I see in the code, PHP just strips everything before last / in
the command path, so does it catch ..'s or does not is not so
relevant. What could be problematic, though - it does not count on path
separator being not / on Windows. This probably indeed needs to be fixed.
--
Stanislav Malyshev, Zend Products Engineer
stas@zend.com http://www.zend.com/ +972-3-6139665 ext.115