in reply to PayPal Advice Sought
The code is ugly and needs serious cleaning up, as you've already noted. Regarding security, I would strictly limit the range of allowable data, and apply all standard tainting practices to this application, as if you were making a system call. By that, I mean you should ignore any extraneous query params, and scrub each POST param to its minimal character set.
I would also use HTTP::Request::Common instead of manually stringing together the POST, and of course check the returned page from PayPal for error or success.
MeowChow s aamecha.s a..a\u$&owag.print
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: PayPal Advice Sought
by epoptai (Curate) on Jul 07, 2001 at 03:37 UTC | |
by ariels (Curate) on Jul 08, 2001 at 01:07 UTC | |
by MeowChow (Vicar) on Jul 08, 2001 at 01:11 UTC | |
by John M. Dlugosz (Monsignor) on Jul 08, 2001 at 02:20 UTC |