6 ms·
He doesn't think the code is bad. Shellshock is not a critical failure in bash. It is a critical failure in thousands of people who knew a tool so useful that
by spindritf 12y ago
He doesn't think the code is bad.
Shellshock is not a critical failure in bash. It is a critical failure in thousands of people who knew a tool so useful that they decided to deploy it far beyond its scope. A tool so resilient that it it did not fall over when everyone deployed against best practices. Everyone knew in the nineties that when you execute a UNIX command with untrusted input, you clear away the environment variables first. Anyone that has untrusted input embedded within a shell script does not know what they are doing. The fact that there is a way to get bash to execute untrusted code is unsurprising. The thing that surprises me is the sheer number of developers who thought it would be otherwise in complete contrast to UNIX parables and common sense.
FTFA.
- clarry 12y agoAnd I never said weev thinks the code is bad. I said what he calls "bashing bash" is other people criticizing bash for having bad code.
- vertex-four 12y ago> Everyone knew in the nineties that when you execute a UNIX command with untrusted input, you clear away the environment variables first. CGI was standardised in 1997 to use environment variables to pass information into the CGI program. I'm sure software existed before that that does the same - procmail, perhaps? No software that's been touched in the past two decades should assume that the environment variable is safe. Especially not a shell, which gets used for all sorts of network-processing-related things.
- nailer 12y agoPostfix is of a similar age and does exactly as weev says.