Full Disclosure mailing list archives
Re: Back To The Future: Unix Wildcards Gone Wild
From: Michal Zalewski <lcamtuf () coredump cx>
Date: Thu, 26 Jun 2014 12:55:42 -0700
We wanted to inform all major *nix distributions via our responsible disclosure policy about this problem before posting it
I'm not sure how to put it mildly, but I think you might have been scooped on this some 1-2 decades ago... Off the top of my head, there's a rant about this behavior in "The Unix-Haters Handbook", and there are several highly detailed articles by David Wheeler published over the years (e.g., http://www.dwheeler.com/essays/filenames-in-shell.html). Yup, it's a counterintuitive behavior that leads to security problems. The odds of changing the semantics at this point are very slim. Other operating systems have their own idiosyncrasies in this area - for example, Windows it not a lot better with parameter splitting and special filenames. /mz _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- Back To The Future: Unix Wildcards Gone Wild defensecode (Jun 26)
- Re: Back To The Future: Unix Wildcards Gone Wild Michal Zalewski (Jun 26)
- Re: Back To The Future: Unix Wildcards Gone Wild Julius Kivimäki (Jun 27)
- Re: Back To The Future: Unix Wildcards Gone Wild fulldisclosure (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild Daniel Miller (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild Nico Le Moin (Jun 29)
- Re: Back To The Future: Unix Wildcards Gone Wild fulldisclosure (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild gremlin (Jun 27)
- Re: Back To The Future: Unix Wildcards Gone Wild Nick Lindridge (Jun 27)
- Re: Back To The Future: Unix Wildcards Gone Wild steel-wing (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild Cley Faye (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild * (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild steel-wing (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild Ivan Delalande (Jun 27)