Re: fetch extension - use local filename from content-disposition header



Martin Cracauer <cracauer@xxxxxxxx> writes:
> The security implications are about the same as for the base
> functionality. Any filename in the current directory can be wiped
> out if you fetch or wget and a URL redirects to another URL which
> leads to a filename that matches.

No. Fetch uses the original filename as specified on the command
line. Redirects are handled behind the scenes by libfetch.

> The default behavior already *is* that the sending server has control
> over your local naming.

No.

DES
--
Dag-Erling Smørgrav - des@xxxxxx

_______________________________________________
freebsd-current@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: fetch extension - use local filename from content-disposition header
    ... suppose any security discussion is good. ... Any filename in the current directory can be wiped out ... >> if you fetch or wget and a URL redirects to another URL which leads to ... FreeBSD keeps the filename derived from the user-given URL, but wget ...
    (freebsd-current)
  • Re: fetch extension - use local filename from content-disposition header
    ... server by users and there handled as "attachments". ... The URL filename ... as a local filename. ... Same if you use the new fetch ...
    (freebsd-current)
  • CUPS installation, ghostscript patch?
    ... I'm installing CUPS and I get the question below. ... I honestly don't know what filename to write. ... => Attempting to fetch from http://www.interq.or.jp/mars/cherry/mac/. ... => MD5 Checksum OK for ghostscript/Font.tar.bz2. ...
    (freebsd-questions)
  • Re: saving .debs to their original name
    ... > What are the bad things that might happen if I just use wget to get ... > the URLs, without using the FILEname? ... I intend to use ... To UNSUBSCRIBE, email to debian-user-request@lists.debian.org ...
    (Debian-User)
  • Re: fetch extension - use local filename from content-disposition header
    ... > The security implications are about the same as for the base ... Any filename in the current directory can be wiped out ... > if you fetch or wget and a URL redirects to another URL which leads to ... If fetch uses a redirected name as its local filename it is seriously ...
    (freebsd-current)