Re: Can System() of Perl be bypassed?
From: FBO (fbo2@gmx.net)
Date: 01/23/03
- Previous message: Tom Arseneault: "RE: Can System() of Perl be bypassed?"
- In reply to: Sandeep Giri: "Can System() of Perl be bypassed?"
- Next in thread: Ian Charnas: "Re: Can System() of Perl be bypassed?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 23 Jan 2003 10:32:27 +0100 From: FBO <fbo2@gmx.net> To: secprog@securityfocus.com
Hi,
On Wed, Jan 22, 2003 at 07:03:27AM -0000, Sandeep Giri wrote:
>
>
> Hi All,
> In my PERL code,I am using user's input as command line argument for the
> program being executed by System().
> Can user run command of his choice by giving malicious input?
> Is PERL's -T (Taint mode) the solution for this?
I do not have any experiences with tainted mode but maybe these lines
will help:
$filename=userinput();
$filenameq=quotemeta($filename);
system("echo $filenameq");
$filename will be interpreted as single parameter.
FBO
- Next message: Ian Charnas: "Re: Can System() of Perl be bypassed?"
- Previous message: Tom Arseneault: "RE: Can System() of Perl be bypassed?"
- In reply to: Sandeep Giri: "Can System() of Perl be bypassed?"
- Next in thread: Ian Charnas: "Re: Can System() of Perl be bypassed?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|