On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 15 of 30:
Next »
« Previous
thankfully, perl can force you to validate your data
I agree with most of what you say. Fortuenately, Perl has a higly documented feature that is recommended in almost every perl web developmentbook/article/<ocument.

use taint;

With these 10 key strokes perl will implicitly mistrust all user supplied data, and cause your program to barf should you use that data without validation.

Of course this feature would make a program like webmin a bit more tedious to write, but since when has security been anything but?
Posted by: spr0ck3t   Posted on: 12/01/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

So is this a flaw...  toadlife | 11/29/05
nope - and here are the details  GDF | 11/30/05
There is nothing wrong with your example  balsover | 11/30/05
It *could* be webmin  diggyk@... | 11/30/05
You are HALF-RIGHT - You are only HALF right - THIS IS NOT A PERL PROBLEM.  jrbeaman | 11/30/05
So is this flaw...  toadlife | 11/29/05
Deja vu  Mr. Big | 11/29/05
Except for the number of posts  Boot_Agnostic | 11/30/05
Sounds more like a webmin flaw  johndoe445566 | 11/30/05
Just like PHPNuke...  Expatriate US Geek | 11/30/05
Quoth Barbie: "Web dev is tough!"  Justin James | 11/30/05
Programming Practices  Yensi717 | 11/30/05
EXACTAMUNDO!  jrbeaman | 11/30/05
Required Reading  springerj | 11/30/05
thankfully, perl can force you to validate your data  spr0ck3t | 12/01/05
Maybe tough but not impossible  rein8 | 12/01/05
Maybe tough but not impossible  rein8 | 12/01/05
Open Source Zealots Dowplay Danger Of Perl Flaw On ZDNet Talkbacks  Rokstar83 | 11/30/05
If you find it offensive...  balsover | 11/30/05
Maybe I didn't make myself clear  Rokstar83 | 11/30/05
Programming not a religion?  jrbeaman | 11/30/05
if that is your opinion then perhaps you are a good example  balsover | 12/01/05
ZDNet didn't write that title  toadlife | 11/30/05
Well in that case...  Rokstar83 | 11/30/05
(nt)I've reported it to ZDNet  toadlife | 11/30/05
Wow!  Loverock Davidson | 11/30/05
On the whole...  John L. Ries | 11/30/05
"I never thought Perl a very good language" ???  jrbeaman | 11/30/05
Not  balsover | 12/01/05
use taint; could have prevented this. webmin is horrible  spr0ck3t | 11/30/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Meet Doc