X-Recipient: archive-cygwin@delorie.com
X-SWARE-Spam-Status: No, hits=-2.0 required=5.0	tests=AWL,BAYES_00,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FROM,RCVD_IN_DNSWL_LOW,T_TO_NO_BRKTS_FREEMAIL
X-Spam-Check-By: sourceware.org
MIME-Version: 1.0
Reply-To: noloader@gmail.com
In-Reply-To: <AANLkTinEUUU+T4YjLH0HFDoXJAvFt6R-6Q_GqhkvXFuy@mail.gmail.com>
References: <AANLkTinEUUU+T4YjLH0HFDoXJAvFt6R-6Q_GqhkvXFuy@mail.gmail.com>
Date: Sun, 12 Dec 2010 11:50:29 -0500
Message-ID: <AANLkTikPSiOxSBt5Nt2ZC05V=gVub5SJ0TiB5T6Maq_H@mail.gmail.com>
Subject: Re: Suspicious EXE named "[.exe" in c:\cygwin\bin?
From: Jeffrey Walton <noloader@gmail.com>
To: cygwin@cygwin.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm
Precedence: bulk
List-Id: <cygwin.cygwin.com>
List-Unsubscribe: <mailto:cygwin-unsubscribe-archive-cygwin=delorie.com@cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe@cygwin.com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-help@cygwin.com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner@cygwin.com
Mail-Followup-To: cygwin@cygwin.com
Delivered-To: mailing list cygwin@cygwin.com

 "[1 =3D 1]" gets an Internal Server error. The PHP is probably trying
to cough up everything....

On Sun, Dec 12, 2010 at 11:44 AM, Jeffrey Walton <noloader@gmail.com> wrote:
> BTW, Since the web interface tried to interpret my input ("Invalid
> regular expression search string"), this database is probably
> vulnerable to a SQL injection.
>
> GNU just got pwn'd
>
> Has anyone tried thew 1 =3D1 trick lately? Are passwords residing in
> another table?
>
> Jeff
>
> Am 12.12.2010 12:29, schrieb Jeffrey Walton:
>> Hi Guys,
>>
>> The executable name is suspicious at best. Attempting to search
>
> On the contrary, it's a standard utility mentioned in IEEE Std 1003.1.
>
>> http://cygwin.com/packages/ results in an error "Invalid regular
>> expression search string: `[.exe`". Quotes, double quotes, and back
>> ticks do not help during the search.
>
> Problem of the web interface.
>
>> What is this program supposed to do?
>
> The same as "test", except that "[" will expect and consume the closing b=
racket.
> =A0Used in scripting with shells that don't have [ built-in.
>
> Details with "man test" ("man [" is missing on my Cygwin system), or in b=
ash
> with "help [".
>
> --
> Matthias Andree
>
> --
> Problem reports: =A0 =A0 =A0 http://cygwin.com/problems.html
> FAQ: =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 http://cygwin.com/faq/
> Documentation: =A0 =A0 =A0 =A0 http://cygwin.com/docs.html
> Unsubscribe info: =A0 =A0 =A0http://cygwin.com/ml/#unsubscribe-simple
>

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

