The problem you are having with taint here is exactly the same problem that you had before you learned how to untaint RealBin. Any time to want to use an external variable, like the $FindBin::RealBin or an $ENV{...} environment variable to access the filesystem, you have to untaint it.
I used the command line on my cPanel-based webhost to prove the point: running DOCUMENT_ROOT=/home1/pryrtcom/public_html perl -T sscce-t.pl :
DOCUMENT ROOT = /home1/pryrtcom/public_html inside eval block to avoid dying on the tainted environment variable Outside of eval block ROOT = /home1/pryrtcom/public_html inside second eval block to avoid dying on the tainted environment var +iable eval 2 didn't die if this prints it did not die because I untainted /home1/pryrtcom/public_html.
source:
Learn the lesson of taint: essentially anytime you use a variable that comes from the outside world, you have to untaint it before using it to access the filesystem. (Second lesson: taint error messages are unhelpful. The problem is not with IO::File, but with using a tainted variable to try to access the filesystem.)
In reply to Re: Insecure Dependency in Taint Mode
by pryrt
in thread Insecure Dependency in Taint Mode
by Bod
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |