note 17143 added to function.escapeshellarg

From: Date: Tue, 27 Nov 2001 19:42:27 +0000
Subject: note 17143 added to function.escapeshellarg
Groups: php.notes 
Request: Send a blank email to php-notes+get-21345@lists.php.net to get a copy of this message
Don't shell out. You shouldn't have to use this function at all if you don't. Shelling out is just asking for security holes even if you escape things. This doesn't stop denial of service attacks. It doesn't save you from buffer overflows in the program you are calling. For filesystem manipulation, use PHP's native functions. The example above is a very bad one, because ls will fail if a directory has too many entries and there are wildcards in the path. If you ABSOLUTELY HAVE to shell out, be sure to escape all characters AND filter the input. Assume everything the user is sending you is bad except for the things you know are ok. The regular expression functions in PHP can help you with this. Never trust user input. -- http://www.php.net/manual/en/function.escapeshellarg.php http://master.php.net/manage/user-notes.php?action=edit+17143 http://master.php.net/manage/user-notes.php?action=delete+17143 http://master.php.net/manage/user-notes.php?action=reject+17143

« previous php.notes (#21345) next »