slides/nyphp-security/shell-cmd-injection.xml
Shell Command Injection
12/15
Stopping Database Command Injection
Escaping Shell Arguments
  • • There can't be command injection if there's no command -- do you really need to run an external program?
  • • Plenty of PHP built-ins for file operations:
  • • mkdir()
  • • rmdir()
  • • copy()
  • • move()
  • • unlink()
  • • chmod()
  • • chown()
  • • chgrp()
  • • ...