in reply to Re: Taint and Shellshock
in thread Taint and Shellshock
While in theory this seems sound, it still feels like the classic black-listing that always seems to fall prey to some clever escaping scheme. Perhaps I'm being paranoid, but it seems like best practice should have any spawned processes firewalled off from anything you didn't explicitly give it.
#11929 First ask yourself `How would I do this without a computer?' Then have the computer do it the same way.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: Taint and Shellshock
by LanX (Saint) on Sep 28, 2014 at 10:00 UTC | |
by kennethk (Abbot) on Sep 29, 2014 at 18:02 UTC | |
by LanX (Saint) on Sep 29, 2014 at 20:27 UTC |