I am actually basing this on what I remember from reading said tutorial by Ovid, where you don't specify what you don't want (which is complicated) but rather specify only what you DO want, and your error message does not give away TOO much information about what went wrong to the user.my ($checked) = $submitted =~ m/^([a-zA-Z0-9])$/; if (!defined $checked) { croak "Invalid name or password.\n" }
In reply to Re: Re: Taint checks on passwords?
by Anonymous Monk
in thread Taint checks on passwords?
by jcpunk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |