In fact, if you use a regex to parse fields out of something, you should mark the extracted fields as tainted unless your regex was carefully constructed to make sure they're safe.
How does one mark a variable as tainted? I did not realize the program had any way to control it directly.
In reply to Re: Re: Back to acceptable untainted characters
by bunnyman
in thread Back to acceptable untainted characters
by bradcathey
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |