in reply to Re: untainting system calls correctly
in thread Untainting system calls correctly
Not to meniton preventing someone from slipping in a username of `-u 0 I0wNj00'.
Update: As a clarification, I mean that by using the multiple arugment form rather than letting the shell split you prevent the user from submitting extra arguments (in the example I gave they could specify that their new account would get a uid of 0).
|
|---|