in reply to Upload Security (strip ../, etc.)
There is a pretty good article in ;login: The Magazine of Usenix and Sage, Volume 25, Number 2 which deals with this. It's in the Effective Perl Programming column by Joseph N Hall. I haven't done an online search to see if it's online or not.
'CGI Barbie says, "Programming is hard!"'
He does a few things to ensure valid directories and pathnames.
These might not be adequate for your needs, but they also might be. He also goes over the basics of use taint. Overall, it's a good little article.
I'll look for it online, and post an update if I find it...
Alan
Update: ;login is online, however only Usenix members can access the most recent issues. Go here to see the issues which are available. The issue I referred to above is April 2000, so it looks like it should be available soon.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
RE: Re: Upload Security (strip ../
by tye (Sage) on Jul 30, 2000 at 08:13 UTC |