Beefy Boxes and Bandwidth Generously Provided by pair Networks
Think about Loose Coupling

Re^2: security and un-tainting paths

by wrinkles (Pilgrim)
on Oct 23, 2011 at 06:47 UTC ( #933166=note: print w/replies, xml ) Need Help??

in reply to Re: security and un-tainting paths
in thread security and un-tainting paths

Graff, thanks for the detailed reply, very much appreciated.

I will fix the ../ possibility in my regex. In fact, the application checks a configuration hash for allowed files, as you suggested. I had suspected that was a security feature, now I know for sure.

The base template and page templates are generally hashrefs which specify HTML::Template templates and other data, but may also run perl code.

It does look like the main executable is called by eval. My desire to run in taint mode is motivated more by my desire to catch newbie mistakes on my part, than by a distrust in the base application (though I do try to cultivate a healthy distrust by default).

Again, thanks for your help, learning opportunities like this help me build a mental framework upon which I can develop with reading on my own.

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://933166]
and the voices are still...

How do I use this? | Other CB clients
Other Users?
Others contemplating the Monastery: (7)
As of 2018-05-27 21:55 GMT
Find Nodes?
    Voting Booth?