Trust me, this is not a bogeyman. merlyn is saying that it is a mistake to think in terms of just trying to remove known dangerous constructs because it is. That way lies madness.<<script (not real script)>script (dirty nasty stuff)>
Decide what you will allow, and explicitly escape everything that does not fit a known and specified safe pattern.
In reply to Re (tilly) 2: Opinions needed on CGI security
by tilly
in thread Opinions needed on CGI security
by Gryphaan
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |