in reply to Re: Re: Future security worries?
in thread Future security worries?
The main thing that suidperl did was allow suid Perl scripts to work even on systems that operate this way.
There is always the danger of a user trying to escape to a shell. That is one of the big reasons that suid shell scripts are disallowed on those systems. The idea behind taint mode is that it will help the programmer to reduce that risk by keeping track of things that come from user input. If the program never uses any input, it can't do anything unexpected (but it might not be able to do anything useful either).
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Re: Re: Future security worries?
by Mr_Person (Hermit) on Jun 09, 2003 at 20:12 UTC | |
|
Re: Re: Re: Re: Future security worries?
by Anonymous Monk on Jun 09, 2003 at 22:07 UTC |