in reply to Re^2: Untainting safely. (b0iler proofing?)
in thread Untainting safely. (b0iler proofing?)
And why you would be passing a date, time, or name near a shell. I'm still confused. That's still thinking from the wrong end.
As for your DROP TABLE example, if you are using placeholders correctly, that value wouldn't matter.
So, I'm still not convinced that there needs to be a standard "untainting" library. When the data is handled properly, we don't need to "match" "safe" data. Period.
-- Randal L. Schwartz, Perl hacker
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: •Re: Re^2: Untainting safely. (b0iler proofing?)
by Anonymous Monk on Jun 26, 2002 at 01:26 UTC | |
by merlyn (Sage) on Jun 26, 2002 at 15:19 UTC | |
by BrowserUk (Patriarch) on Jun 26, 2002 at 21:28 UTC | |
by merlyn (Sage) on Jun 26, 2002 at 21:44 UTC | |
by BrowserUk (Patriarch) on Jun 26, 2002 at 22:54 UTC | |
|
Re: •Re: Re^2: Untainting safely. (b0iler proofing?)
by epoptai (Curate) on Jun 26, 2002 at 00:38 UTC |