in reply to Insecure dependency in open
As others have mentioned, Perl automatically runs in taint mode when it is setuid or setgid. That is almost always the right thing to do, but if you don't like it, you can always recompile your copy of Perl with that code commented out. You could also blindly untaint all of your data, run your program under sudo instead of making it setgid, or write a wrapper program which sets up the GIDs then exec's a copy of the real program, which if you're careful will not be running in taint mode.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Insecure dependency in open
by argv (Pilgrim) on Jan 22, 2007 at 05:02 UTC | |
by sgifford (Prior) on Jan 22, 2007 at 05:15 UTC | |
by halley (Prior) on Jan 22, 2007 at 14:32 UTC | |
by argv (Pilgrim) on Jan 22, 2007 at 18:31 UTC | |
by ikegami (Patriarch) on Jan 22, 2007 at 18:49 UTC | |
by argv (Pilgrim) on Jan 22, 2007 at 19:21 UTC | |
| |
by Fletch (Bishop) on Jan 22, 2007 at 19:54 UTC | |
by argv (Pilgrim) on Jan 22, 2007 at 22:07 UTC | |
| |
by Anonymous Monk on Jan 22, 2007 at 05:33 UTC |