On last.fm: Ciara radio - Listen now!
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 5 of 30:
Next »
« Previous
You are HALF-RIGHT - You are only HALF right - THIS IS NOT A PERL PROBLEM.
ANY code that uses user or form supplied data, must be prechecked for reasonableness. Example, I see $1000 per month shoppingcarts allow an email address to be entered, and saved in the phonenumber field.
It is programmers that forget 90% of the code they write has nothing to do with processing, but making sure the user doesn't screw up the system or the data. You MUST PRE-TEST ALL USER INPUT PEOPLE!

The tools we have are fantastic, but also make it easy for neophites to pawn themselves off as IT Professionals, which is a big fat lie. Because
of this, we have a TON of bad code out there.

You are wide open with PHP too, so be careful where you store data and what inside values you show in your code. Most .asp code also uses XML
and can wreak havoc with modified web forms and pages. I use ONLY my own Perl code, NO PHP, no XML, and very little javascript, and of course standard HTML with a sprinkling of SSI and Style Sheets thrown in for flavor.

THIS IS NOT A PERL PROBLEM.

It is an idiot with a computer problem.
Especially those that only THINK they are professionals because even dummer customers buy their stuff.

(IMHO)
Posted by: jrbeaman   Posted on: 11/30/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

So is this a flaw...  toadlife | 11/29/05
nope - and here are the details  GDF | 11/30/05
There is nothing wrong with your example  balsover | 11/30/05
It *could* be webmin  diggyk@... | 11/30/05
You are HALF-RIGHT - You are only HALF right - THIS IS NOT A PERL PROBLEM.  jrbeaman | 11/30/05
So is this flaw...  toadlife | 11/29/05
Deja vu  Mr. Big | 11/29/05
Except for the number of posts  Boot_Agnostic | 11/30/05
Sounds more like a webmin flaw  johndoe445566 | 11/30/05
Just like PHPNuke...  Expatriate US Geek | 11/30/05
Quoth Barbie: "Web dev is tough!"  Justin James | 11/30/05
Programming Practices  Yensi717 | 11/30/05
EXACTAMUNDO!  jrbeaman | 11/30/05
Required Reading  springerj | 11/30/05
thankfully, perl can force you to validate your data  spr0ck3t | 12/01/05
Maybe tough but not impossible  rein8 | 12/01/05
Maybe tough but not impossible  rein8 | 12/01/05
Open Source Zealots Dowplay Danger Of Perl Flaw On ZDNet Talkbacks  Rokstar83 | 11/30/05
If you find it offensive...  balsover | 11/30/05
Maybe I didn't make myself clear  Rokstar83 | 11/30/05
Programming not a religion?  jrbeaman | 11/30/05
if that is your opinion then perhaps you are a good example  balsover | 12/01/05
ZDNet didn't write that title  toadlife | 11/30/05
Well in that case...  Rokstar83 | 11/30/05
(nt)I've reported it to ZDNet  toadlife | 11/30/05
Wow!  Loverock Davidson | 11/30/05
On the whole...  John L. Ries | 11/30/05
"I never thought Perl a very good language" ???  jrbeaman | 11/30/05
Not  balsover | 12/01/05
use taint; could have prevented this. webmin is horrible  spr0ck3t | 11/30/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

SmartPlanet

Click Here