![]() |
|
go ahead... be a heretic | |
PerlMonks |
Re (tilly) 1: Run arbitrary UNIX commands on webserver without telnetby tilly (Archbishop) |
on Oct 30, 2001 at 19:39 UTC ( #122103=note: print w/replies, xml ) | Need Help?? |
I far prefer the tried and true:
The proper usage of this handy command runner I leave to your imagination, a close read of open's semantics, and a reminder that if you know how to do a URI encoding, you can put pipes etc into the filename. Yes. This is a warning about a basic security mistake that you may be making without realizing it...
In Section
Craft
|
|