#48345 [Opn]: system() function docs: how to prevent cmd.exe
| From: | giosp at panozzo dot it | Date: | Thu, 21 May 2009 18:09:54 +0000 |
| Subject: | #48345 [Opn]: system() function docs: how to prevent cmd.exe | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-2288@lists.php.net to get a copy of this message | ||
ID: 48345
User updated by: giosp at panozzo dot it
-Summary: system() funciotn docs: how to prevent cmd.exe
Reported By: giosp at panozzo dot it
Status: Open
Bug Type: Documentation problem
Operating System: Windows 2003
PHP Version: Irrelevant
New Comment:
-
Previous Comments:
------------------------------------------------------------------------
[2009-05-20 15:49:44] giosp at panozzo dot it
Description:
------------
In the documentation of system(), exec(), shell_exec(), popen(),
passthru() and other external proces execution function there should be
the following notes:
1. All these functions does not execute the requested process directly:
they execute a shell (cmd.exe ? bash ? which criteria is used ?
%COMSPEC% in windows ?).
2. Executing the standard CMD.EXE in windows is not possible when
running as a non administrator user, so these function will fail in a
standard IIS environment, where the current PHP script is executed as
ISUR_MACHINENAME
3. The only secure way to execute a process in windows bypassing
cmd.exe, is to use the proc_open() function with the option
"bypass_shell"
Reproduce code:
---------------
---
From manual page: function.system
---
<?php
passthru("ping www.hp.com");
?>
Expected result:
----------------
A typical ping output
Actual result:
--------------
Warning: passthru() [function.passthru]: Unable to fork [ping
www.hp.com] in C:\Inetpub\wwwroot\prova.php on line 2
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=48345&edit=1