Jimmy Hess mysidia at gmail.com
Thu Sep 25 01:27:39 UTC 2014

On Wed, Sep 24, 2014 at 7:41 PM, Chris Adams <cma at cmadams.net> wrote:
> Has anybody looked to see if the popular web software the users install
> and don't maintain (e.g. Wordpress, phpBB, Joomla, Drupal) use system()

Wouldn't it be great if it was JUST  system()?   It's also  popen(),
shell_exec(),  passhru(),  exec(),  backtic operator.

I am pretty sure ALL of them use at least 1 of these in various places
out of the box,  and many plugins use these as well,  such that a
shell could be invoked,  but  popen() on $sendmail is  particularly

> or the like to call out to external programs?  What about service
> provider type stuff like RT?  I know Nagios calls out to shell scripts


More information about the NANOG mailing list