Perl code security (CGI related)
"Rick Zhong" <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <047401c41b06$b477f290$fcce13ac@gamelink> |
hi, I was looking at this vulnerable cgi-code. i have tidy it a bit ==================================================== my $code = 'require '. "\"$default/" .$area. '.pm"; $lang ='. $area. '->new();'; eval $code; ==================================================== The $default is under user's control. My question is whether perl's eval function allow execution of command such as "rm -rf *". Any execution restriction of "eval"? I have tried on my perl v5.8. It seems the "eval $code" can successfully change the behaviour of variables in the programs. However it does not have any effect if $code is shell command such as "rm -rf *"... The cgi program is running on apache 2.0 running under user apache. Let me know if you need any details of my questions. It will be very helpful if you can give any demo code etc. regards, Rick ========================================== Welcome to www.sinfosec.org SINgapore <In>FOSECurity Interest Group