Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One shouldn't construct shell commands from untrusted user input in the first place unless they know exactly what they're doing and is aware of all the pitfalls. It's the worst possible tool to be using if the aim is to avoid security issues with minimal effort. Debating about this particular curl quirk distracts from the bigger issue IMO.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: