4 ms·
This is awful. Shell commands are not guaranteed to be idempotent, people! These should all be of the form exec($_POST, not exec($_GET.
by ephemeralgomi 12y ago
This is awful. Shell commands are not guaranteed to be idempotent, people! These should all be of the form exec($_POST, not exec($_GET.
- RutZap 12y agoI think the problem here is the fact that tainted variables (user input) are used to execute shell commands. it doesn't matter if that's $_POST or $_GET, both of these are user input and therefore these are huge vulnerabilities.
- saurik 12y ago"That's the joke."
- masklinn 12y agoI'm pretty sure GP was being sarcastic.
- RutZap 12y agoWhoops! My bad.. now I feel stupid :)
- huseyinkeles 12y agoI think he is being sarcastic.
- oleganza 12y agoI think he was indeed sarcastic.
- deleted 12y ago[deleted]
- gnurag 12y agoI think he is indeed being sarcastic.
- cassm 12y agoI think he is was being indeed sarcastic.
- kvcrawford 12y agoI'm sorry, but I can't hear you over the sound of the joke flying overhead.
- izietto 12y agoIt depends by the command, echo is idempotent for example. There should be some checking like $cmdname = split(' ', $_GET['command']); if(!in_array(IDEMPOTENT_COMMANDS, $cmdname)) echo '<h1>Your request is not guaranteed to be idempotent. Please use a POST.</h1>'; else exec($_GET['command'] ...
- TeMPOraL 12y agoif(!in_array(IDEMPOTENT_COMMANDS, $cmdname)) { header("HTTP/1.1 405 Method Not Allowed"); die(); } Fixed ;).
- 12y ago
- RoryH 12y agoLove the sarcasm ;-)
- venomsnake 12y agoI prefer exec($_REQUEST when I have to do something like that. You capture both get and post variables.
- deleted 12y ago[deleted]