I thought it would add some security to the program I'm making. As it is now I just filter param values as I use them with very strict patterns. Works good and there are no problems. That seems to be the "Best Practice" when dealing with param values.
I plan to release the final version to the public and the more I think about adding any security filter globally to the param's. I realize it could actually trick a developer into thinking they don't need to check the param's for issues.
So "no" on filtering null bytes is the answer I'm leaning to.
That is not the only thing I wanted to talk about.
I see in CGI there is a way to limit POST only, but no possible way to limit GET or the Cookies.
Is there a reason why those are not needed?