Other nomination
You can't securely execute commands on Windows
On Windows, process creation implicitly launches the command interpreter for batch files, and that interpreter ignores the backslash escaping language runtimes apply to arguments. A user-controlled argument passed to a batch file, or to any command named without an extension, breaks out of the quoting and runs attacker commands across many language runtimes.
Record
- Researcher
- RyotaK
- Published by
- GMO Flatt Security Research
- Date
In the archive
Related sources
- Haskell BatBadBut advisory
- PHP BatBadBut advisory
- Rust BatBadBut advisory
- Node.js BatBadBut security release
Tags
This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host.