in reply to Re^2: Why do poisoned null attacks still work ?
in thread Why do poisoned null attacks still work ?
Yes, but unless you plan to replace even more of the OS by Perl, what better way of opening a file do you see than asking the OS to open it?
Of course, Perl could try to wrap all C APIs that are known to take a C string and prevent passing a filename to them that contains a \0, but enabling Taint mode does about the same unless you're actively opening that door again.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^4: Why do poisoned null attacks still work ?
by ikegami (Patriarch) on Jul 22, 2009 at 17:10 UTC | |
by Corion (Patriarch) on Jul 22, 2009 at 21:24 UTC | |
by ikegami (Patriarch) on Jul 22, 2009 at 22:53 UTC | |
by Anonymous Monk on Jul 23, 2009 at 00:45 UTC | |
by ikegami (Patriarch) on Jul 23, 2009 at 03:43 UTC | |
|