[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Why is *splitting every word* is a shell security hole?
From: |
alex xmb sw ratchev |
Subject: |
Re: Why is *splitting every word* is a shell security hole? |
Date: |
Thu, 22 Aug 2024 00:31:19 +0200 |
oh im sorry i miss these topic things ..
.. greets ..
On Wed, Aug 21, 2024, 11:05 PM Greg Wooledge <greg@wooledge.org> wrote:
> On Wed, Aug 21, 2024 at 20:57:46 +0200, alex xmb sw ratchev wrote:
> > IFS+=h
> >
> > nm , thxx
> >
> > and you get to run it the next time the user uses `echo'.
>
> VAR+=content is a bash extension, which would definitely not work in
> the Bourne shells where splitting of literal words happened.
>
>