Re: fetch extension - use local filename from content-dispositionheader
- From: Martin Cracauer <cracauer@xxxxxxxx>
- Date: Fri, 30 Dec 2005 08:10:45 -0500
Andrey Chernov wrote on Fri, Dec 30, 2005 at 06:57:24AM +0300:
> On Thu, Dec 29, 2005 at 10:33:48PM -0500, Matt Emmerton wrote:
> > > Forbidding "/" will set the security to the same level as the base
> > > functionality. I like that.
> >
> > Agreed, although it still leaves open all the security loopholes that were
> > mentioned, given the proper cwd and malicious intent on the server end.
>
> What about "../../../../../../../../../../../../sbin/init" ?
Of course I meant I will not allow *any* "/" in the filename.
Might have been lost in the translation.
Martin
--
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
Martin Cracauer <cracauer@xxxxxxxx> http://www.cons.org/cracauer/
FreeBSD - where you want to go, today. http://www.freebsd.org/
_______________________________________________
freebsd-current@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@xxxxxxxxxxx"
- References:
- Re: fetch extension - use local filename from content-disposition header
- From: Martin Cracauer
- Re: fetch extension - use local filename from content-dispositionheader
- From: Matt Emmerton
- Re: fetch extension - use local filename from content-dispositionheader
- From: Andrey Chernov
- Re: fetch extension - use local filename from content-disposition header
- Prev by Date: Re: fetch extension - use local filename from content-disposition header
- Next by Date: Re: Cleanup for config(8)
- Previous by thread: Re: fetch extension - use local filename from content-dispositionheader
- Next by thread: Re: fetch extension - use local filename from content-dispositionheader (new diff)
- Index(es):
Relevant Pages
|
|