in reply to Re: Re: Hash Clash on purpose
in thread Hash Clash on purpose
Which would only allow foo, bar, and baz, and silently drop everything else from the URL. But that kind of breaks the standalone nature of many cgi programs, and would need to be checked for/cleaned prior to actually parsing the parameters. On a plus side this could lead to many many more sights being far more secure than they presently are as its one more obstacle to hurdle in the never ending hunt for other people's processing cycles. Kinda like 'use strict' for CGI :)use CGI; my $cgi = new CGI; $cgi->allow_param( qw(foo,bar,baz) );
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Re: Re: Hash Clash on purpose
by iburrell (Chaplain) on Jun 02, 2003 at 22:57 UTC | |
|
Re: Re: Re: Re: Hash Clash on purpose
by mr_mischief (Monsignor) on Jun 03, 2003 at 02:52 UTC | |
|
Re: Re: Re: Re: Hash Clash on purpose
by Anonymous Monk on Jun 04, 2003 at 08:20 UTC |