Suspicious EXE named "[.exe" in c:\cygwin\bin?
Jeffrey Walton
noloader@gmail.com
Sun Dec 12 17:13:00 GMT 2010
"[1 = 1]" gets an Internal Server error. The PHP is probably trying
to cough up everything....
On Sun, Dec 12, 2010 at 11:44 AM, Jeffrey Walton <noloader@gmail.com> wrote:
> BTW, Since the web interface tried to interpret my input ("Invalid
> regular expression search string"), this database is probably
> vulnerable to a SQL injection.
>
> GNU just got pwn'd
>
> Has anyone tried thew 1 =1 trick lately? Are passwords residing in
> another table?
>
> Jeff
>
> Am 12.12.2010 12:29, schrieb Jeffrey Walton:
>> Hi Guys,
>>
>> The executable name is suspicious at best. Attempting to search
>
> On the contrary, it's a standard utility mentioned in IEEE Std 1003.1.
>
>> http://cygwin.com/packages/ results in an error "Invalid regular
>> expression search string: `[.exe`". Quotes, double quotes, and back
>> ticks do not help during the search.
>
> Problem of the web interface.
>
>> What is this program supposed to do?
>
> The same as "test", except that "[" will expect and consume the closing bracket.
> Used in scripting with shells that don't have [ built-in.
>
> Details with "man test" ("man [" is missing on my Cygwin system), or in bash
> with "help [".
>
> --
> Matthias Andree
>
> --
> Problem reports: http://cygwin.com/problems.html
> FAQ: http://cygwin.com/faq/
> Documentation: http://cygwin.com/docs.html
> Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple
>
--
Problem reports: http://cygwin.com/problems.html
FAQ: http://cygwin.com/faq/
Documentation: http://cygwin.com/docs.html
Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple
More information about the Cygwin
mailing list