in reply to RE: Warning our Fellow Monks
in thread Warning our Fellow Monks
Your best bet is to use tokens in your URL submissions, and then map those tokens to a set of filenames. If that can't be arranged, use a regular expression to "untaint" the data by explicitely declaring permitted characters.
($secure) = ($tainted =~ /(\w+)/); open(F, "< $secure") or die "$!"; # read only "../../bin/ls -l /etc|" -> "bin" (no such file)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
(Ovid - Duking it out over security) RE(3): Warning our Fellow Monks
by Ovid (Cardinal) on Oct 12, 2000 at 00:28 UTC | |
by dchetlin (Friar) on Oct 12, 2000 at 03:16 UTC |