top | item 46640439

(no title)

PhilipRoman | 1 month ago

This is completely safe: [ "${payload}" -eq 42 ]

This can evaluate arbitrary code: [[ "${payload}" -eq 42 ]]

Here is one example of a malicious payload:

  payload='a[$(touch /tmp/pwned)]'

discuss

order

ndsipa_pomu|1 month ago

Thanks.

Now I need to figure out whether (( payload == 42 )) is safe.