-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

>
> Note that the password starts with a !2 . That in shell didn't work.

Quite right, as well as characters such as &(){} and maybe others.

Personally, I do not ever specify the password on the command line,  
because it shows up in the process list (bad on multiuser systems)  
and it will also get recorded in .bash_history

It's actually a very similar concept as sql injection too, if one  
were to put a command like this in a script and accept outside input  
into it.

David Morton
Maia Mailguard http://www.maiamailguard.com
[EMAIL PROTECTED]



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Darwin)

iD8DBQFGqgVeUy30ODPkzl0RAuEoAJ9/h6QdCVYKEoayWB9MemKHHd3ujQCfcO37
vbEC50ERKnAFCFy+PZpBpsY=
=zj3p
-----END PGP SIGNATURE-----
_______________________________________________
Tracks-discuss mailing list
[email protected]
http://lists.rousette.org.uk/mailman/listinfo/tracks-discuss

Reply via email to