# PHP Code Not Working As It's Supposed To

**URL:** https://forum.infinityfree.com/t/php-code-not-working-as-its-supposed-to/70608
**Category:** Hosting Support
**Created:** [January 6, 2023, 5:21am UTC](https://forum.infinityfree.com/t/php-code-not-working-as-its-supposed-to/70608 "2023-01-06T05:21:08Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![anon43252847](https://forum.infinityfree.com/letter_avatar/anon43252847/32/5_5575768a8748004e209b776fc1b2916d.png) [@anon43252847](https://forum.infinityfree.com/u/anon43252847)
#### Post date: [January 6, 2023, 5:21am UTC](https://forum.infinityfree.com/t/php-code-not-working-as-its-supposed-to/70608/1 "2023-01-06T05:21:08Z")

</div>

So this is where the problem’s happening: reverse-text.epizy.com  
It’s supposed to return: “Reversed text: “.desrever eb ot txet elpmaS” from “Sample text to be reversed.”.” when I input “Sample text to be reversed.”  
However it returns “Reversed text: “” from “Sample text to be reversed.”.”  
It could be something with my php code but I’ve tested it in my local PHP development server and it does what it’s supposed to do.  
There’s no error message too.

---

<div class="post-metadata">

### Author: ![Admin](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/admin/32/36437_2.png) [@Admin](https://forum.infinityfree.com/u/Admin)
#### Post date: [January 6, 2023, 10:01am UTC](https://forum.infinityfree.com/t/php-code-not-working-as-its-supposed-to/70608/2 "2023-01-06T10:01:11Z")

</div>

I checked your code and I see the issue.

I see you’re doing the string reversing by executing a shell command through `shell_exec`. However, running shell commands is blocked on our hosting, and all functions related to it are blocked.

Instead of doing the string reversal in bash through shell\_exec, why not do it through PHP itself? PHP has the function `strrev` that does exactly what you need it to do.

And unlike using `shell_exec`, doing string manipulation through PHP doesn’t create a massive, gaping Remote Code Execution vulnerability in your code if your don’t meticulously filter and escape everything you put in the shell commands (which you don’t do at all).

---

<div class="post-metadata">

### Author: ![anon43252847](https://forum.infinityfree.com/letter_avatar/anon43252847/32/5_5575768a8748004e209b776fc1b2916d.png) [@anon43252847](https://forum.infinityfree.com/u/anon43252847)
#### Post date: [January 6, 2023, 10:15pm UTC](https://forum.infinityfree.com/t/php-code-not-working-as-its-supposed-to/70608/3 "2023-01-06T22:15:33Z")

</div>

Oh, I did not know you can’t run shell commands in infinityfree or that `shell_exec` is a vulnerable command. I’ll just use `strrev` instead.

---

<div class="post-metadata">

### Author: ![Admin](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/admin/32/36437_2.png) [@Admin](https://forum.infinityfree.com/u/Admin)
#### Post date: [January 7, 2023, 10:18am UTC](https://forum.infinityfree.com/t/php-code-not-working-as-its-supposed-to/70608/4 "2023-01-07T10:18:08Z")

</div>

`shell_exec` isn’t necessarily a vulnerable command, but just like with a database query, you need to check your input or you’ll create a vulnerability in your code. Just like you should never put unfiltered form data into a database query, you should never put unfiltered form data into a system command.

Native PHP functions don’t have this issue (except for things like `eval` of course), so they are much safer to use.

---

<div class="post-metadata">

### Author: ![system](https://infinityfree-forum-uploads.s3.dualstack.eu-central-1.amazonaws.com/original/3X/b/0/b024fd3fa88bae093c9576e55c2c94e33f890206.svg) [@system](https://forum.infinityfree.com/u/system)
#### Post date: [January 14, 2023, 10:18am UTC](https://forum.infinityfree.com/t/php-code-not-working-as-its-supposed-to/70608/5 "2023-01-14T10:18:42Z")

</div>

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.
