RE: exec( ) function on winNT

From: Date: Wed, 12 Jul 2000 11:19:42 +0000
Subject: RE: exec( ) function on winNT
Groups: php.general php.windows 
Request: Send a blank email to php-general+get-6119@lists.php.net to get a copy of this message
Yes or No. Everything that is run by PHP under NT should be run as the owner or the webserver. But i would test it yourself, try deleting things with exec("delete c:\winnt") and see what happens :) You should also make sure that any user data that is passed to the command line isnt a problem. escapeshell (or whatever) _may_ not be right for NT. EG: you may have exec("mkdir $foo"); (Maybe you should just set a few files and direectories secured to other users and groups, then try deleting them) Be aware that it may be possible for a user to set $foo to " anyfile/r/ndelete c:\winnt" or maybe "afile | delete c:\winnt" i dont know what would happen.. but you should try em out, (This is why you should completely avoid exec and the like in any tool with user input, they are one of the more causes of security breaches) mn Mark Nold markn@alverstone.com.au Systems Consultant Change is inevitable, except from vending machines. On Wednesday, 12 July 2000 11:51, Anurag Bhalla [SMTP:anuragbhalla@id.eth.net] wrote: > Hie > > I want to know if the exec( ) function which runs a command line operation > pose any threat to NT security ie is the execution of this function banned by win NT > environment. > > U c a n a ns w e r j u s t Y e s or N o, b u t p l s a n s w e r > > Thanx > Anurag > > >

« previous php.general (#6119) next »