It makes me super uncomfortable that globbing in Bash can turn into code execution. The fact that the name of a file can change the behavior of ls is scary. This also works for other commands that you tend to glob with, such as rm.
It makes me super uncomfortable that globbing in Bash can turn into code execution. The fact that the name of a file can change the behavior of ls is scary. This also works for other commands that you tend to glob with, such as rm.
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/Lee_Holmes/statuses/114473456490599222 on your instance and quote it. (Note that quoting is not supported in Mastodon.)