PerlTaintCheck and configuration for secure paths

by geektron (Curate)
on Jun 22, 2006 at 17:44 UTC

in reply to Re: PerlTaintCheck and configuration for secure paths
in thread PerlTaintCheck and configuration for secure paths

$thumbName is constructed in the code. because of that, i thought it didn't need extra sanitizing.

I'll test it w/ Scalar::Util to ensure that's the tainted part ...

Re^3: PerlTaintCheck and configuration for secure paths
on Jun 22, 2006 at 17:51 UTC
    If $thumbName was constructed with whatsoever variable that is tainted and not sanitized, it becomes tainted as well.

    In perlsec is a snippet of code:

    sub is_tainted { return ! eval { eval("#" . substr(join("", @_), 0, 0)); 1 }; }
      the operative phrasing i missed: *not sanitized* ... after re-reading perlsec for the 3231244^34 time today, the "not sanitized" part kicked in.

Node Type: note [id://556961]
