Bod,

The problem you are having with taint here is exactly the same problem that you had before you learned how to untaint RealBin. Any time to want to use an external variable, like the $FindBin::RealBin or an $ENV{...} environment variable to access the filesystem, you have to untaint it.

I used the command line on my cPanel-based webhost to prove the point: running DOCUMENT_ROOT=/home1/pryrtcom/public_html perl -T sscce-t.pl :

DOCUMENT ROOT = /home1/pryrtcom/public_html inside eval block to avoid dying on the tainted environment variable Outside of eval block ROOT = /home1/pryrtcom/public_html inside second eval block to avoid dying on the tainted environment var +iable eval 2 didn't die if this prints it did not die because I untainted /home1/pryrtcom/public_html.

source:

Learn the lesson of taint: essentially anytime you use a variable that comes from the outside world, you have to untaint it before using it to access the filesystem. (Second lesson: taint error messages are unhelpful. The problem is not with IO::File, but with using a tainted variable to try to access the filesystem.)


In reply to Re: Insecure Dependency in Taint Mode by pryrt
in thread Insecure Dependency in Taint Mode by Bod

Title:
Use:  <p> text here (a paragraph) </p>
and:  <code> code here </code>
to format your post, it's "PerlMonks-approved HTML":



  • Posts are HTML formatted. Put <p> </p> tags around your paragraphs. Put <code> </code> tags around your code and data!
  • Titles consisting of a single word are discouraged, and in most cases are disallowed outright.
  • Read Where should I post X? if you're not absolutely sure you're posting in the right place.
  • Please read these before you post! —
  • Posts may use any of the Perl Monks Approved HTML tags:
    a, abbr, b, big, blockquote, br, caption, center, col, colgroup, dd, del, details, div, dl, dt, em, font, h1, h2, h3, h4, h5, h6, hr, i, ins, li, ol, p, pre, readmore, small, span, spoiler, strike, strong, sub, summary, sup, table, tbody, td, tfoot, th, thead, tr, tt, u, ul, wbr
  • You may need to use entities for some characters, as follows. (Exception: Within code tags, you can put the characters literally.)
            For:     Use:
    & &amp;
    < &lt;
    > &gt;
    [ &#91;
    ] &#93;
  • Link using PerlMonks shortcuts! What shortcuts can I use for linking?
  • See Writeup Formatting Tips and other pages linked from there for more info.