in reply to Re^4: Runtime Taint Enable
in thread Runtime Taint Enable
Now consider this file listing:use warnings; use strict; foreach my $file (<*>) { if ($file =~ m/(.*)/) { #we trust everything from *our* box $file = $1; my $rc = system("rm", $file); } }
Whoops!-rw-rw-r-- 1 thulben thulben 1 Feb 24 11:03 -rf -rwxr-xr-x 1 thulben thulben 254 Feb 24 10:59 unsafe.pl*
thor
Feel the white light, the light within
Be your own disciple, fan the sparks of will
For all of us waiting, your kingdom will come
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^6: Runtime Taint Enable
by Rhandom (Curate) on Feb 24, 2005 at 18:37 UTC |