Re: Bug #11890 Updated: linux exploitable
| From: | Zak Greant | Date: | Thu, 05 Jul 2001 07:48:42 +0000 |
| Subject: | Re: Bug #11890 Updated: linux exploitable | ||
| References: | 1 | Groups: | php.dev php.dev php.dev |
| Request: | Send a blank email to php-dev+get-59298@lists.php.net to get a copy of this message | ||
Derick wrote:
> As far as I can see does shell_arg only escape the ' and shell_cmd the
> following characters: #&;`'\"|*?~<>^()[]{}$\\\x0A\xFF so I think
> _shell_cmd would be the best choice.
This is probably a nit-picking point that I should not have
wasted your time with. :) Here was my reasoning for recommending
_shell_arg over _shell_cmd:
_shell_cmd escapes a range of characters to render them safe
to use as part of a shell argument. It uses the strategy of
escaping meta-characters and control operators with a
leading backslash so that they are interpreted as literal
values.
_shell_arg single quotes a string, and converts any existing
single quotes (') in the value are to '\''. This sequence
temporarily ends the single-quoted string, inserts a literal
single quote, and then resumes the string.
Shells don't interpret *anything* inside of a single quoted
string, making this a very safe strategy (IMUO)
However, given that no one cognizant of these matters has
made the same recommendation, you are probably quite safe
in your original choice! :)
--zak