BugTraq
Re: Vulnerability in multiple "now playing" scripts for various IRC clients Aug 15 2007 04:27PM
v9 fakehalo us (2 replies)
Re: Vulnerability in multiple "now playing" scripts for various IRC clients Aug 16 2007 06:57PM
Wouter Coekaerts (wouter coekaerts be)
Re: Vulnerability in multiple "now playing" scripts for various IRC clients Aug 15 2007 05:34PM
Michael Tharp (gxti partiallystapled com)
v9 (at) fakehalo (dot) us [email concealed] wrote:
> I may be rusty with knowledge about mirc (say almost 10 years out of date)...but, in what situation would the pipe ('|') ever be processed from a variable, even if it was read from a mp3 ID3?

This is probably a bigger concern for *nix scripts, especially of the
homebrew variety where the owner hacks something out in 20 minutes and
never looks at it again. While the attacker might not have access to the
source code, they shouldn't have any problems defeating simple
substitution onto a command line.

-- m. tharp

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus