3 ms·
QUERY_STRING, REQUEST_URI and others are set according to the HTTP request in my environment. Could be Rack/Rails – I haven't checked yet. Edit: Oh, I see now
by molf 12y ago
QUERY_STRING, REQUEST_URI and others are set according to the HTTP request in my environment. Could be Rack/Rails – I haven't checked yet.
Edit: Oh, I see now – you're right: they don't actually change on each request. Tested with %x{env > /tmp/env}.
Thanks for your clarifications!
- FooBarWidget 12y agoThose are not system environment variables (which is what is used to exploit bash). Those are Rack environment variables, which are stored in an entirely different manner, and have no effect on bash. We do set system environment variables for REQUEST_URI, QUERY_STRING, etc, but only during process spawning. Which is why I suggested configuring a static process pool. In Phusion Passenger 5, we will no longer set system environment variables for REQUEST_URI, QUERY_STRING, etc because of a major architectural overhaul. This also accidentally happens to work around Shellshock.