From owner-freebsd-current@FreeBSD.ORG Fri Dec 30 04:28:34 2005 Return-Path: X-Original-To: freebsd-current@freebsd.org Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6A12816A41F; Fri, 30 Dec 2005 04:28:34 +0000 (GMT) (envelope-from jmg@hydrogen.funkthat.com) Received: from hydrogen.funkthat.com (gate.funkthat.com [69.17.45.168]) by mx1.FreeBSD.org (Postfix) with ESMTP id E54E243D45; Fri, 30 Dec 2005 04:28:33 +0000 (GMT) (envelope-from jmg@hydrogen.funkthat.com) Received: from hydrogen.funkthat.com (localhost.funkthat.com [127.0.0.1]) by hydrogen.funkthat.com (8.13.3/8.13.3) with ESMTP id jBU4S9xC045737; Thu, 29 Dec 2005 20:28:10 -0800 (PST) (envelope-from jmg@hydrogen.funkthat.com) Received: (from jmg@localhost) by hydrogen.funkthat.com (8.13.3/8.13.3/Submit) id jBU4S8nh045736; Thu, 29 Dec 2005 20:28:08 -0800 (PST) (envelope-from jmg) Date: Thu, 29 Dec 2005 20:28:08 -0800 From: John-Mark Gurney To: Andrey Chernov , Matt Emmerton , Martin Cracauer , Barney Wolff , freebsd-current@freebsd.org, Sean Bryant Message-ID: <20051230042807.GA68143@funkthat.com> Mail-Followup-To: Andrey Chernov , Matt Emmerton , Martin Cracauer , Barney Wolff , freebsd-current@FreeBSD.ORG, Sean Bryant References: <20051229221459.A17102@cons.org> <030d01c60cf1$db80a290$1200a8c0@gsicomp.on.ca> <20051230035724.GA52167@nagual.pp.ru> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20051230035724.GA52167@nagual.pp.ru> User-Agent: Mutt/1.4.2.1i X-Operating-System: FreeBSD 5.4-RELEASE-p6 i386 X-PGP-Fingerprint: B7 EC EF F8 AE ED A7 31 96 7A 22 B3 D8 56 36 F4 X-Files: The truth is out there X-URL: http://resnet.uoregon.edu/~gurney_j/ X-Resume: http://resnet.uoregon.edu/~gurney_j/resume.html Cc: Subject: Re: fetch extension - use local filename from content-dispositionheader X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: John-Mark Gurney List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 30 Dec 2005 04:28:34 -0000 Andrey A. Chernov wrote this message on Fri, Dec 30, 2005 at 06:57 +0300: > On Thu, Dec 29, 2005 at 10:33:48PM -0500, Matt Emmerton wrote: > > > Forbidding "/" will set the security to the same level as the base > > > functionality. I like that. > > > > Agreed, although it still leaves open all the security loopholes that were > > mentioned, given the proper cwd and malicious intent on the server end. > > What about "../../../../../../../../../../../../sbin/init" ? last I checked there was a / or two in that filename... :) and hence invalid... -- John-Mark Gurney Voice: +1 415 225 5579 "All that I will do, has been done, All that I have, has not."