in reply to Using -T on an Apache server
A quick search gives Too late for "-T"? and Confused about Taint.
I suggest you read up on exact what tainting is, and how to effectively (see 2nd update) untaint data - man perlsec is your friend.
Cheers.
Baz.
Update: You might want to look at Ovid's CGI tutorial, which has info on taint mode amoungst other things. Ovid++
Further update: I guess I should be a little more helpful...data is normally untainted by checking that it matches the sort of input you are expecting to be passed into your script for security/sanity.
The effective part of my comment is on this point - make sure that you allow _only_ what you expect - there is a way of untainting all data, but if you do that, you're opening yourself up to a World of Pain.
For example: if you're expecting a single digit number, check for the presence of a single digit in the input - if it's something other than that throw an error and do not process the data any further.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Using -T on an Apache server
by Satanya (Novice) on Jan 11, 2002 at 23:23 UTC |