in reply to Re: Back to acceptable untainted characters
in thread Back to acceptable untainted characters
In fact, if you use a regex to parse fields out of something, you should mark the extracted fields as tainted unless your regex was carefully constructed to make sure they're safe.
How does one mark a variable as tainted? I did not realize the program had any way to control it directly.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Back to acceptable untainted characters
by jonadab (Parson) on Sep 09, 2003 at 02:40 UTC | |
by bunnyman (Hermit) on Sep 09, 2003 at 15:40 UTC |