in reply to Why do poisoned null attacks still work ?
Taint mode does that, and more. It forces the programmer to specify and launder what form of input they require. If you don't use Taint mode in your publically accessible programs, or are too generous in whitewashing your input data, that's still a fault of the programmer though.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Why do poisoned null attacks still work ?
by ikegami (Patriarch) on Jul 22, 2009 at 14:37 UTC | |
by Corion (Patriarch) on Jul 22, 2009 at 15:39 UTC | |
by ikegami (Patriarch) on Jul 22, 2009 at 17:10 UTC | |
by Corion (Patriarch) on Jul 22, 2009 at 21:24 UTC | |
by ikegami (Patriarch) on Jul 22, 2009 at 22:53 UTC | |
| |
|
Re^2: Why do poisoned null attacks still work ?
by pubnoop (Acolyte) on Jul 22, 2009 at 14:48 UTC | |
by Anonymous Monk on Jul 22, 2009 at 20:02 UTC | |
by JavaFan (Canon) on Jul 22, 2009 at 14:58 UTC |