Re: Homegrown Pseudo-Tainting

by ChOas (Curate)
on Mar 15, 2002 at 09:36 UTC ( #151945=note: print w/ replies, xml ) Need Help??

in reply to Homegrown Pseudo-Tainting

Just to add to all the posters above, who focus more on
untainting the data, perldoc perlsec gives this example
to beforehand check if the data is actually tainted:

sub is_tainted { return ! eval { join('',@_), kill 0; 1; }; }


print "profeth still\n" if /bird|devil/;

Comment on Re: Homegrown Pseudo-Tainting
Replies are listed 'Best First'.
Re: Re: Homegrown Pseudo-Tainting
by gellyfish (Monsignor) on Mar 15, 2002 at 11:49 UTC

    Except that will only do what you want when you have used the '-T' switch. And as the person who asked the question said they can't use '-T' ..


