Beefy Boxes and Bandwidth Generously Provided by pair Networks
Perl-Sensitive Sunglasses
 
PerlMonks  

Re^10: The Most Essential Perl Development Tools Today (vulnerability)

by tye (Cardinal)
on Jan 12, 2013 at 06:47 UTC ( #1013012=note: print w/ replies, xml ) Need Help??


in reply to Re^9: The Most Essential Perl Development Tools Today (guessing)
in thread The Most Essential Perl Development Tools Today

Yeah, an earlier draft of my response included a description of how I wasn't at all worried about somebody being able to inject code into my Perl script and then deciding that the thing to do with that power is to use some syntax ambiguity.

It seems pretty silly to me, especially since the attacker would have to inject the code before my code is compiled. You can't theorize some "stack overflow" attack doing it.

But reading the article, I saw that they weren't describing what I would call a "vulnerability". The example was clearly somebody introducing the error by accident. They even described it as "with the best intentions".

So I deleted the argument about how I didn't care about the "vulnerability" angle and considered whether I was worried about the "oops" angle. I tend to actually worry about "oops" possibilities. But this one didn't seem very plausible to me, especially not the way I program.

- tye        


Comment on Re^10: The Most Essential Perl Development Tools Today (vulnerability)
Re^11: The Most Essential Perl Development Tools Today (vulnerability)
by BrowserUk (Pope) on Jan 12, 2013 at 09:43 UTC
    They even described it as "with the best intentions".

    This misanthrope accidentally defined BAD as GOOD "with the best of intentions"? Right.

    And having made the change, ran the tests and nothing failed before it went into production? Right.

    :)


    With the rise and rise of 'Social' network sites: 'Computers are making people easier to use everyday'
    Examine what is said, not who speaks -- Silence betokens consent -- Love the truth but pardon error.
    "Science is about questioning the status quo. Questioning authority".
    In the absence of evidence, opinion is indistinguishable from prejudice.

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://1013012]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others taking refuge in the Monastery: (6)
As of 2014-10-25 20:38 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    For retirement, I am banking on:










    Results (148 votes), past polls