Beefy Boxes and Bandwidth Generously Provided by pair Networks
We don't bite newbies here... much
 
PerlMonks  

Re^2: Ideas Wanted for Perl::Critic Security Policies

by davidrw (Prior)
on Jul 01, 2006 at 00:40 UTC ( #558708=note: print w/ replies, xml ) Need Help??


in reply to Re: Ideas Wanted for Perl::Critic Security Policies
in thread Ideas Wanted for Perl::Critic Security Policies

Using the 3-parameter form of open would be a good practice to check for.
There's a InputOutput::ProhibitTwoArgOpen in the Perl::Critic distro already..

The DBI one would be a 'challenge' :) .. not sure how it'd be possible to distinguish between $dbh->prepare("update table set my_val = $somevalue") (NOT OK) and $dbh->prepare("update $TABLENAME set my_val = ?") (OK) without actually parsing the sql .. plus there's the circumvention of $sql = "update table set my_val = $somevalue"; $sth=$dbh->prepare($sql); as well (or can you back-trace that w/PPI?)..

I took a crack at the system/exec one (see RFC: Perl-Critic policy: ProhibitInlineSystemArgs), though i think there's problems catching all of those, too.. e.g. system( join(" ", $cmd, @args) )


Comment on Re^2: Ideas Wanted for Perl::Critic Security Policies
Select or Download Code

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://558708]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others pondering the Monastery: (6)
As of 2014-09-20 06:51 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    How do you remember the number of days in each month?











    Results (155 votes), past polls