It's a well-written article, but with one major flaw. It discusses the problems of passing unchecked user data to shell commands, but doesn't mention taint mode which is there to prevent you doing just that.
--
"Perl makes the fun jobs fun
and the boring jobs bearable" - me
In reply to Re: Re: Re: Re: A rumination on finding secure scripts, versus rolling-your-own
by davorg
in thread A rumination on finding secure scripts, versus rolling-your-own
by Hero Zzyzzx
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |