I was under the impression that if you were doing anything unsafe with tainted data, a reasonable amount of testing would flush that out
Sure. But testing is done by people. People make mistakes. Computer is here to help us. It's not perfect, but once you decide you like tainting, why remove it? Perhaps the computer will find more mistakes later.
Please note that I do not use -T unless when automatically enabled.
Juerd # { site => 'juerd.nl', plp_site => 'plp.juerd.nl', do_not_use => 'spamtrap' }
In reply to Re: Re: Why do I need -w in a cgi script
by Juerd
in thread Why do I need -w in a cgi script
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |