in reply to Re (tilly) 2: Opinions needed on CGI security
in thread Opinions needed on CGI security
... and that's the sum total of the CGI's interaction with the rest of the world, what could a hacker (or anyone) do that's evil? Now, if you will (say) be outputting a web page based on this data later on that's a different story... but that's not the question.$a = "some CGI data <<script blah blah evil stuff"; open (F, ">>file.txt"); print F $a;
My point is that I agree wholeheartedly that we should be as diligent as necessary to secure our programs and our data. But at some point (and this is a good example) "diligence" turns into unecessary paranoia.
Gary Blackburn
Trained Killer
Update: Ok, so maybe the point from the original poster was to use the data to populate a web page. :-P Seems to me in that case that there's no reliable way of filtering out all possible evil HTML/Javascript (please, someone correct me if there is). But other than that, what else does the poster need to do?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Re (tilly) 2: Opinions needed on CGI security
by AgentM (Curate) on Feb 14, 2001 at 09:56 UTC | |
|
Re (tilly) 4: Opinions needed on CGI security
by tilly (Archbishop) on Feb 14, 2001 at 17:17 UTC | |
|
Reroh Rorge: Opinions needed on CGI security
by baku (Scribe) on Feb 14, 2001 at 19:33 UTC | |
|
Re: Re: Re (tilly) 2: Opinions needed on CGI security
by MeowChow (Vicar) on Feb 14, 2001 at 09:37 UTC | |
|
Re:(tilly) 2: Opinions needed on CGI security
by Gryphaan (Beadle) on Feb 14, 2001 at 17:42 UTC |