in reply to Tainted or bad characters
There aren't lists I know of, but the usual practice is to have a default deny...that is, strip out anything that you don't explicitly allow. So something like:
my $text = $q->param('text'); # Removes any character that ISN'T a digit, word, or space character $text =~ s/[^\d\w\s]+//g;
In the end though, what characters to allow/disallow all depends on how you are using the data later. Maybe you could explain this more?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Tainted or bad characters
by waswas-fng (Curate) on Jul 28, 2003 at 19:15 UTC | |
by Anonymous Monk on Jul 28, 2003 at 22:21 UTC | |
by diotalevi (Canon) on Jul 28, 2003 at 22:33 UTC |