[Info-vax] Command Line Versus Command Line
Michael S
already5chosen at yahoo.com
Fri May 24 09:32:25 EDT 2024
On Fri, 24 May 2024 08:13:04 -0400
Arne Vajhøj <arne at vajhoej.dk> wrote:
>
> As illustrated by the Rust issue.
>
I was not able to figure out what exactly Rust guys were trying to
achieve. Feeding cmd.exe with command line from untrusted source and
expecting no harm sounds like mission impossible.
That is, impossible when you run cmd.exe under privileged account.
It is possible when you run it under sufficiently deprived account, but
that is orthogonal to parsing of command line.
More information about the Info-vax
mailing list