I seem to see this all too often. Input is filtered against a few regexes and assumed safe for processing. the true solution to security involves refusing input that doesn't match a criterion and that's IT. In attempt for userfriendliness, it is sometimes attempted to work around this as i see above but this can and will result in security holes that you really can't afford. So again, one filter- pass/fail.
In reply to Re: CGI and Traceroute
by AgentM
in thread CGI and Traceroute
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |