in reply to Using -T on an Apache server

A quick search gives Too late for "-T"? and Confused about Taint.

I suggest you read up on exact what tainting is, and how to effectively (see 2nd update) untaint data - man perlsec is your friend.

Cheers.

Baz.

Update: You might want to look at Ovid's CGI tutorial, which has info on taint mode amoungst other things. Ovid++

Further update: I guess I should be a little more helpful...data is normally untainted by checking that it matches the sort of input you are expecting to be passed into your script for security/sanity.
The effective part of my comment is on this point - make sure that you allow _only_ what you expect - there is a way of untainting all data, but if you do that, you're opening yourself up to a World of Pain.
For example: if you're expecting a single digit number, check for the presence of a single digit in the input - if it's something other than that throw an error and do not process the data any further.

Replies are listed 'Best First'.
Re: Re: Using -T on an Apache server
by Satanya (Novice) on Jan 11, 2002 at 23:23 UTC

    Thanks for the info... I will search right away..

    Tanya