Beefy Boxes and Bandwidth Generously Provided by pair Networks
good chemistry is complicated,
and a little bit messy -LW

Re: Stay aware of security

by rpc (Monk)
on Mar 15, 2001 at 22:37 UTC ( #64744=note: print w/replies, xml ) Need Help??

in reply to Stay aware of security

I fully agree; system and network security are of utmost importance, especially in a threat model which includes large loss of revenue.

However, most people think that security is reading about the latest exploits and techniques. This is not enough.

Security must be pro-active. Most public exploits have been known to the blackhat community for a very long time. Devise an overall security architecture that matches your threat model.

Also, I can't tell you how many times during a security audit I've compromised machines through finding holes in home grown code. Yes, worry about patching and maintaining your daemons, but damnit have someone security audit your source!

On the Perl front, CGI scripts tend to be the worst in security, and best in accesibility. This is due to the overwhelming amount of novice Perl coders who have web whacking jobs.

In particular, please, please, please: if you load a template or any dynamic content via a CGI script don't get the template or content filename from the client if you can help it. I have (legally) compromised dozens of websites using insecure template loading alone.

In short, audit your code!

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://64744]
[LanX]: copy and paste the text into your Petroza's scratchpad please
[Petroza]: yes I'll do that. instead of the url I'll write "link"
[LanX]: darn my pc is restarting for updates

How do I use this? | Other CB clients
Other Users?
Others cooling their heels in the Monastery: (11)
As of 2017-10-17 15:31 GMT
Find Nodes?
    Voting Booth?
    My fridge is mostly full of:

    Results (233 votes). Check out past polls.