doqw89029 2013-12-18 17:54
浏览 32
已采纳

来自php脚本安全的mysqldump

If I do shell_exec('mysqldump DATABASE_NAME') from a php script, is there any danger?

Is there a way to get this to work in Windows?

I am going to use mysqldump for database backup from a web page

Also should I do set_time_limit(0) when running this?

  • 写回答

1条回答 默认 最新

  • dounai9294 2013-12-18 18:47
    关注

    Yeah, there is danger: If database name comes from an untrusted source hackers could try to inject shell commands in the database name. For example:

    $dbname = 'test; cat /etc/shadow';
    

    might being used to obtain user names and encrypted passwords from the system (depends on the system)..

    To avoid that, you should use escapeshellarg() to quote the database name (and possible other arguments):

    shell_exec('mysqldump ' . escapeshellarg($database_name));
    

    set_time_limit() isn't required if you are following my hints here


    Needless to say, that you'll have to secure the page using login.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 请问有人会紧聚焦相关的matlab知识嘛?
  • ¥15 网络通信安全解决方案
  • ¥50 yalmip+Gurobi
  • ¥20 win10修改放大文本以及缩放与布局后蓝屏无法正常进入桌面
  • ¥15 itunes恢复数据最后一步发生错误
  • ¥15 关于#windows#的问题:2024年5月15日的win11更新后资源管理器没有地址栏了顶部的地址栏和文件搜索都消失了
  • ¥100 H5网页如何调用微信扫一扫功能?
  • ¥15 讲解电路图,付费求解
  • ¥15 有偿请教计算电磁学的问题涉及到空间中时域UTD和FDTD算法结合的
  • ¥15 three.js添加后处理以后模型锯齿化严重