in reply to Re: Taint tracing a single variable?
in thread Taint tracing a single variable?

I've decided to bite the bullet and just taint-check the whole thing. Once the CGI params have been detainted properly, then I can add a manual taint to the X-Forwarded-For value and see what tainted() will show, closer to the DBI calls.

Does DBI do taint checking on its own?

Thanks!

Replies are listed 'Best First'.
Re^3: Taint tracing a single variable?
by RonW (Parson) on May 21, 2014 at 21:35 UTC

    I would be surprised if DBI had taint checking built in. But I've never actually tried to test that.