Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Depends if they `execve` or run the command inside a shell.

I'd bet for (1), but who knows.



redirections aren't parsed by exec....


Indeed, I read the command's template too fast. Well, in this case it's worrysome


Controlling arguments without shell often still leads to RCE though, because a lot of software has some flag that runs some command

https://0x90909090.blogspot.com/2015/07/no-one-expect-comman...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: