RE: Perl code security (CGI related)

jnf <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

just a small addendum, i think [i havent done much perl stuff in a year or 
two, and what i have done has mostly been little one liners], but i think 
that you would need $code to look like:

$code = "system(\"ls\");\x00";

to keep it from concatenating the rest of the variables to the string, i 
could be incorrect there. just my 4 peso's.


j



- -- 

It is only the great men who are truly obscene.  If they had not dared to 
be obscene, they could never have dared to be great.
                -- Havelock Ellis
 


On Mon, 5 Apr 2004, Michael Silk wrote:

> Rick,
> 
>   All you need to do is figure out how to execute a shell
>   command in perl code ... i imagine its something like:
>   ---------------
>   system("ls");
>   ---------------
> 
>   So you would modify the value of "$default" such that it
>   this:
>   ---------------
>   eval $code;
>   ---------------
> 
>   looks like this, at runtime:
>   ---------------
>   eval "system(\"ls\");";
>   ---------------
> 
>   Hope thats clear ....
> 
> -- Michael
> 
> 
> 
> -----Original Message-----
> From: Rick Zhong [mailto:[email protected]]
> Sent: Monday, 5 April 2004 10:08 PM
> To: [email protected]
> Subject: Perl code security (CGI related)
> 
> 
> hi,
> I was looking at this vulnerable cgi-code. i have tidy it a bit
> 
> ====================================================
> my $code = 'require '. "\"$default/" .$area. '.pm"; $lang ='. $area.
> '->new();';
> 
> 	eval $code;
> ====================================================
> 
> The $default is under user's control. My question is whether perl's eval
> function allow execution of command such as "rm -rf *". Any execution
> restriction of "eval"? I have tried on my perl v5.8. It seems the "eval
> $code" can successfully change the behaviour of variables in the programs.
> However it does not have any effect if $code is shell command such as
> "rm -rf *"...
> 
> The cgi program is running on apache 2.0 running under user apache. Let
> me
> know if you need any details of my questions. It will be very  helpful
> if
> you can give any demo code etc.
> 
> regards,
> Rick
> 
> 
> 
> 
> 
> 
> 
> ==========================================
> Welcome to www.sinfosec.org
> SINgapore <In>FOSECurity Interest Group
> 
> 
> 
> 
> 
> 
> Concerned about your privacy? Follow this link to get
> FREE encrypted email: https://www.hushmail.com/?l=2
> 
> Free, ultra-private instant messaging with Hush Messenger
> https://www.hushmail.com/services.php?subloc=messenger&l=434
> 
> Promote security and make money with the Hushmail Affiliate Program: 
> https://www.hushmail.com/about.php?subloc=affiliate&l=427
> 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (OpenBSD)

iD8DBQFAckOYsKAeTAhLiCERAt0gAJ9LlMo1qhMnJ4GtA2I6wxLhIImkJgCffR5X
Bl7i5c6ClPlK17IM681Ev6s=
=kWWt
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.