Collected research
You can't securely execute commands on Windows
BatBadBut: You can't securely execute commands on Windows
On Windows, process creation implicitly launches the command interpreter for batch files, and that interpreter ignores the backslash escaping language runtimes apply to arguments. A user-controlled argument passed to a batch file, or to any command named without an extension, breaks out of the quoting and runs attacker commands across many language runtimes.
Record
- Document
- BatBadBut: You can't securely execute commands on Windows
- Researcher
- RyotaK
- Published by
- GMO Flatt Security Research
- Date
- Topic
- Other
In the archive
Related sources
- Haskell BatBadBut advisory Advisory
- PHP BatBadBut advisory Advisory
- Rust BatBadBut advisory Advisory
- Node.js BatBadBut security release
Tags
This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .