pie__ has joined #nixos-security
pie___ has quit [Ping timeout: 255 seconds]
periklis has joined #nixos-security
erictapen has joined #nixos-security
pie_ has joined #nixos-security
periklis has quit [Ping timeout: 245 seconds]
<
pie_>
so apparently I had some misunderstandings about how bash works
<
pie_>
is it possible to get a file named $(echo hi) to make echo hi execute without using eval?
<
pie_>
i cant really elaborate for "eh?" xP
<
gchristensen>
you have a file named ./$(echo hi)?
<
pie_>
well, not normally no
<
pie_>
I was just wondering about doing bad things
<
gchristensen>
right, but in your scenario, that is what has happened?
pie___ has joined #nixos-security
<
pie___>
im basically wondering about code injection through file names
pie_ has quit [Ping timeout: 246 seconds]
<
gchristensen>
sure
pie___ has quit [Remote host closed the connection]
pie_ has joined #nixos-security
<
pie_>
not sure whats up with my network
<
gchristensen>
not 100% sure
<
gchristensen>
but if your filename has a * in it you can get bit by globbing
pie_ has quit [Ping timeout: 246 seconds]
pie_ has joined #nixos-security
pie_ has quit [Ping timeout: 250 seconds]
pie_ has joined #nixos-security