The difference is that instead of starting with a set of safe characters, you attempt to guess what are all the unsafe ones. You are much more likely to miss an unsafe character in this way.
No, you always decide what are safe characters, and then you remove everything that isn't on that list.
In reply to Re^8: Taint mode limitations
by Anonymous Monk
in thread Taint mode limitations
by alain_desilets
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |