6 ms·
Because it is treating all of these intended side-effects of using a shell as though they are security vulnerabilities. The problem is that there is a way for
by jcape 11y ago
Because it is treating all of these intended side-effects of using a shell as though they are security vulnerabilities.
The problem is that there is a way for untrusted user input to ever touch a shell in the first place.
Seriously, I challenge you to find a language reference that doesn't decry the use of their version of system(3)---because all that does is run the given command under the user's shell.
- ajkjk 11y agoSure, fine, but why the anger? Why the 'trainwreck'? that's not constructive at all. The article definitely didn't claim these were security vulnerabilities - only that they were surprising. Some of these were surprising to me too. Am I an idiot for not knowing these? (no, I'm not, I'm just a novice). It's really aggravating to learn something from an article that is making someone more knowledgeable this angry without explanation.