note 17143 added to function.escapeshellarg
| From: | tmorganNOSPAM at NOSPAMnetcnct dot net | Date: | Tue, 27 Nov 2001 19:42:27 +0000 |
| Subject: | note 17143 added to function.escapeshellarg | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-21345@lists.php.net to get a copy of this message | ||
Don't shell out. You shouldn't have to use this function at all if you don't.
Shelling out is just asking for security holes even if you escape things. This doesn't stop
denial of service attacks. It doesn't save you from buffer overflows in the program you are
calling.
For filesystem manipulation, use PHP's native functions. The example above is a very bad one,
because ls will fail if a directory has too many entries and there are wildcards in the path.
If you ABSOLUTELY HAVE to shell out, be sure to escape all characters AND filter the input. Assume
everything the user is sending you is bad except for the things you know are ok. The regular
expression functions in PHP can help you with this.
Never trust user input.
--
http://www.php.net/manual/en/function.escapeshellarg.php
http://master.php.net/manage/user-notes.php?action=edit+17143
http://master.php.net/manage/user-notes.php?action=delete+17143
http://master.php.net/manage/user-notes.php?action=reject+17143