in reply to Re: Is there such a thing as safe eval?
in thread Is there such a thing as safe eval?
With all due respect, every time you come up with something to remove, I and others can come up with something bad to put in there. For example, how would you "sanitize" the following (given the caveat that I didn't make it dangerous):
$_ = 'sub _{local $_=shift;y/A-Z/a-z/;y/0-9//d;$_}$_=q{P1R2I3N4T "R0M +-F0R"};s/(.*)/_($1)/sexe'; eval;
Cheers,
Ovid
New address of my CGI Course.
Silence is Evil (feel free to copy and distribute widely - note copyright text)
|
|---|