Re: Bug #11890 Updated: linux exploitable

From: Date: Thu, 05 Jul 2001 07:48:42 +0000
Subject: Re: Bug #11890 Updated: linux exploitable
References: 1  Groups: php.dev php.dev php.dev 
Request: Send a blank email to php-dev+get-59298@lists.php.net to get a copy of this message
Derick wrote: > As far as I can see does shell_arg only escape the ' and shell_cmd the > following characters: #&;`'\"|*?~<>^()[]{}$\\\x0A\xFF so I think > _shell_cmd would be the best choice. This is probably a nit-picking point that I should not have wasted your time with. :) Here was my reasoning for recommending _shell_arg over _shell_cmd: _shell_cmd escapes a range of characters to render them safe to use as part of a shell argument. It uses the strategy of escaping meta-characters and control operators with a leading backslash so that they are interpreted as literal values. _shell_arg single quotes a string, and converts any existing single quotes (') in the value are to '\''. This sequence temporarily ends the single-quoted string, inserts a literal single quote, and then resumes the string. Shells don't interpret *anything* inside of a single quoted string, making this a very safe strategy (IMUO) However, given that no one cognizant of these matters has made the same recommendation, you are probably quite safe in your original choice! :) --zak

« previous php.dev (#59298) next »