#48345 [Opn->Asn]: system() function docs: how to prevent cmd.exe

From: Date: Sun, 21 Jun 2009 19:03:59 +0000
Subject: #48345 [Opn->Asn]: system() function docs: how to prevent cmd.exe
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-2383@lists.php.net to get a copy of this message
ID: 48345 Updated by: bjori@php.net Reported By: giosp at panozzo dot it -Status: Open +Status: Assigned Bug Type: Documentation problem Operating System: Windows 2003 PHP Version: Irrelevant -Assigned To: +Assigned To: kalle Previous Comments: ------------------------------------------------------------------------ [2009-05-21 18:09:53] giosp at panozzo dot it - ------------------------------------------------------------------------ [2009-05-20 15:49:44] giosp at panozzo dot it Description: ------------ In the documentation of system(), exec(), shell_exec(), popen(), passthru() and other external proces execution function there should be the following notes: 1. All these functions does not execute the requested process directly: they execute a shell (cmd.exe ? bash ? which criteria is used ? %COMSPEC% in windows ?). 2. Executing the standard CMD.EXE in windows is not possible when running as a non administrator user, so these function will fail in a standard IIS environment, where the current PHP script is executed as ISUR_MACHINENAME 3. The only secure way to execute a process in windows bypassing cmd.exe, is to use the proc_open() function with the option "bypass_shell" Reproduce code: --------------- --- From manual page: function.system --- <?php passthru("ping www.hp.com"); ?> Expected result: ---------------- A typical ping output Actual result: -------------- Warning: passthru() [function.passthru]: Unable to fork [ping www.hp.com] in C:\Inetpub\wwwroot\prova.php on line 2 ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=48345&edit=1

« previous php.doc.bugs (#2383) next »