in reply to Reading ENV variable and using that in taint mode
Yes, setting the %ENV values you want to use within the program is exactly how to untaint them. Your method is a little more elaborate than I would usually use, but it looks fine to me.
Rather than arrays, I would probably work directly with the strings. The arrays have some nice features, though.
You can avoid the need to detaint PATH by using the absolute location of /bin/ls, which is unix standard.
After Compline,
Zaxo
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Reading ENV variable and using that in taint mode
by sara2005 (Scribe) on Jun 27, 2006 at 23:24 UTC | |
by Zaxo (Archbishop) on Jun 27, 2006 at 23:51 UTC | |
by Sidhekin (Priest) on Jun 28, 2006 at 02:00 UTC | |
by Anonymous Monk on Jul 12, 2006 at 03:54 UTC |