Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

(a) Below is a short POST-method CGI script - it reads a line of the form field-name=value from standard input, and then executes the last

image text in transcribed

(a) Below is a short POST-method CGI script - it reads a line of the form field-name=value" from standard input, and then executes the last command (in the line $result = 'last ...') to see if the user name "value has logged in recently. Describe how to construct an input that executes an arbitrary command with the privileges of the script. Explain how your input will cause the program to execute your command, and suggest how the code could be changed to avoid the problem. #!/usr/bin/perl print "content-type: text/html "; ($field_name, $username_to_look_for) = split(/=/, ); chomp $username_to_look_for; $result = 'last -1000 i grep $username_to_look_for'; if ($result) { print "$username_to_look_for has logged in recently. "; } else { print "$username_to_look_for has NOT logged in recently. "; print "

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Main Memory Database Systems

Authors: Frans Faerber, Alfons Kemper, Per-Åke Alfons

1st Edition

1680833243, 978-1680833249

More Books

Students also viewed these Databases questions

Question

2. Identify issues/causes for the apparent conflict.

Answered: 1 week ago

Question

3. What strategies might you use?

Answered: 1 week ago