logoalt Hacker News

ddtayloryesterday at 4:30 PM2 repliesview on HN

I think there is an easier substitution attack since there is shell expansion occuring. I will toy with it later today.


Replies

PhilipRomanyesterday at 7:00 PM

The array indexing thing is a special case in [[...]] which is otherwise more-or-less secure (no expansion occurs under typical unquoted variable access). https://news.ycombinator.com/item?id=46631811

faresfayesterday at 7:52 PM

[dead]