|Resolving security issues
|Page 1 of 1|
|Author:||kovzol [ Thu Nov 08, 2012 1:31 pm ]|
|Post subject:||Resolving security issues|
I am a new member here, but I use Singular with lots of joy since last year. I recently created SingularWebService (code.google.com/p/singularws/) to make it possible to run Singular commands remotely via HTTP, primarily for using it with GeoGebra (geogebra.org).
Today I learned that the
system("sh",...)command may be a security hole in SingularWS. Thus I added the
--no-shellcommand line option at github.com/kovzol/Sources/commit/9442e1298e604074c4cbc5643a8d965f59939b93 to prevent entering arbitrary shell command remotely. (SingularWebService is an anonymous service.)
If my change is acceptable for the developers, I would be happy if you could merge this enhancement to the official version.
Thank you and best regards,
Research Assistant at the Department of Mathematics Education
Johannes Kepler University Linz, Austria
|Page 1 of 1||All times are UTC + 1 hour [ DST ]|
|Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group