Re: pre-announce exmh-2.7.2
| Newsgroups | gmane.mail.exmh.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 05 Jan 2005 08:32:32 PST, Brent Welch said: > file tail protects against filenames with any leading components. > > set filename "foo;echo 'hibrent::0:0::::' >> /etc/passwd;baz" > > file tail $filename > => passwd;baz Hmm.. Yeah, that does work for the leading-components part, but you still need to regexp $filename to rid it of any shell metachars. I didn't do it in FSBox because I *wanted* a filename like ../../etc/passwd to show up in the dialog box as .._.._etc_passwd so that you'd *see* that somebody was playing games with you. Otherwise an attacker could feed you some long string of maliciousness and end it with "/something.innocent", and you'd never suspect somehting was up unless you went and looked at the actual MIME headers... (Of course, maybe I'm just being over-paranoid because I'm *paid* to be a tin-foil-helmet paranoid.. ;) _______________________________________________ Exmh-workers mailing list [email protected] https://www.redhat.com/mailman/listinfo/exmh-workers
signature.asc
(application/pgp-signature, 226 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQFB3B0KcC3lWbTT17ARAohBAKC2ibig/yJq2xlDZfP0h3ZOV85phACeJVcC a1j1jD9ZS0tE0SiIUk2uJlw= =6Qgm -----END PGP SIGNATURE-----