To the tune of "Now I lay me down to sleep..."
As I bring my script online,
I pray that taint will keep things fine.
But should it die or get cracked,
I pray my server has been backed.
Use CGI; that's the stuff.
One wonders, though, if it's enough?
Find the loophole and backdoor.
Read the FAQ's, then read some more.
Hide the data. Fix the paths.
Write your code as Lincoln has.
Limit uploads. Launder stuff.
Trust not the user. Man, that's rough.
Hide the data from the page.
Hacking prices is all the rage.
Encrypt cookies and id's.
Store data in tables, please.
Are permissions set rightly?
Are the passwords hidden tightly?
It runs; it works. Does it rate?
Is my résumé up-to-date?
Security, noble yen.
It's very stressful, now and then.
With appropriate apologies to Sondheim Lerner, Loewe, and any one else who feels they're necessary.
--f
Update: Oops. Me, bad. Misremembered the credits for the ObRef. Fixed. Sorry.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: An Apprentice's Lament
by royalanjr (Chaplain) on Apr 06, 2001 at 23:33 UTC |