Beefy Boxes and Bandwidth Generously Provided by pair Networks
Keep It Simple, Stupid
 
PerlMonks  

Perl is a secure language (as far as it can be)

by arhuman (Vicar)
on Sep 04, 2001 at 17:21 UTC ( #110028=note: print w/replies, xml ) Need Help??


in reply to Secrets & Lies & Perl

Yes Perl is vulnerable as almost every computer language.
(Race condition,NULL poison...)
But Perl has some feature that you could use to greatly reduce the risks :
  • Suidperl
  • The Taint mode
  • The automatic memory allocation
  • Modified (s)printf (no format string attack..)
  • Tons of open sourced robust security tools/modules : For encrypting, signing, communicating...

Perl provides you many tools to produce safe code, but also enough freedom to screw your security...

Anyway, to my mind, the security shouldn't be enforced by the language but by the programmer.
You should better watch carefully your code logic to ensure security
(this combined with a decent OS (which excludes windows ;-) should provide enough security)

UPDATE :
Don't hesitate to use Super Search with 'security' as keyword to find tons of interesting threads...
Perlsec and the Camel's chapter about security should be mandatory too...

"Only Bad Coders Code Badly In Perl" (OBC2BIP)
  • Comment on Perl is a secure language (as far as it can be)

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://110028]
help
Chatterbox?
[RonW]: Tunnel FTP through stunnel?
[james28909]: i guess i should have done it in perl. i bet it woulnt have taken me 5 hours to figure out haha
[choroba]: In the end, I was able to upgrade Perl from 5.8.3 to 5.22 and install Net::SFTP::Foreign , at least for the task involved
[james28909]: what would be the best way to capture that stream with perl? ffmpeg args -rtp rtp://127.0.0.1?
[LanX]: if I was forced to talk about all security risks I encountered oO
[james28909]: if i did that with ffmpeg, i could then listen on the port with perl right?
[LanX]: one of my clients filtered a menu linking to Web pages according to user rights. .. but he didn't secure the access to those unlisted pages

How do I use this? | Other CB clients
Other Users?
Others drinking their drinks and smoking their pipes about the Monastery: (11)
As of 2017-05-22 21:45 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?