in reply to Extra CGI.pm safety by stripping \x00 bytes?
Certainly the null byte can appear in utf-8; code points like \x2400, \x2500, . . . all have them.
The poison null cracks from perl all occur where C code looks at perl strings and takes them as null-delimited C strings. That typically happens when the string is fed to system and interpreted by the shell. Your caution is justified there, but not as a blanket ban on null bytes.
Update: Oops! Thanks, guys++, I didn't know that.</blush>
After Compline,
Zaxo
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Extra CGI.pm safety by stripping \x00 bytes?
by dave_the_m (Monsignor) on May 26, 2005 at 20:58 UTC | |
|
Re^2: Extra CGI.pm safety by stripping \x00 bytes?
by marnanel (Beadle) on May 26, 2005 at 21:16 UTC | |
|
Re^2: Extra CGI.pm safety by stripping \x00 bytes?
by rlucas (Scribe) on May 26, 2005 at 19:56 UTC |