/
githubmirror
/
curl
Обзор
Документация
Войти
/
githubmirror
/
curl
Код
Запросы
0
Пакеты
0
Релизы
0
Аналитика
Безопасность
master
tests/data/test2115
46 строк
895 B
Alhuda Khan
ftp: reject control bytes in ACCT and alternative-to-user
13 июл 2026, 09:46
Не верифицирован
13 июл 2026, 09:46
9494750
Код
Авторство
О чём код?
<?xml version="1.0" encoding="US-ASCII"?> <testcase> <info> <keywords> FTP ACCT </keywords> </info> # Server-side <reply> <servercmd> REPLY PASS 332 please provide account name </servercmd> </reply> # Client-side <client> <server> ftp </server> <name> FTP --ftp-account with embedded CRLF is rejected </name> # read the account from a config file so the raw CR LF reaches curl intact <file name="%LOGDIR/test%TESTNUMBER.config"> ftp-account = "one\r\nDELE %TESTNUMBER" </file> <command> ftp://%HOSTIP:%FTPPORT/%TESTNUMBER -K %LOGDIR/test%TESTNUMBER.config </command> </client> # Verify data after the test has been "shot" <verify> # 43 - CURLE_BAD_FUNCTION_ARGUMENT <errorcode> 43 </errorcode> # the account is rejected before ACCT is built, so the injected DELE command # must never reach the server <protocol crlf="yes"> USER anonymous PASS ftp@example.com </protocol> </verify> </testcase>