Beefy Boxes and Bandwidth Generously Provided by pair Networks
Your skill will accomplish
what the force of many cannot
 
PerlMonks  

Re^2: security and un-tainting paths

by wrinkles (Monk)
on Oct 23, 2011 at 06:47 UTC ( #933166=note: print w/ replies, xml ) Need Help??


in reply to Re: security and un-tainting paths
in thread security and un-tainting paths

Graff, thanks for the detailed reply, very much appreciated.

I will fix the ../ possibility in my regex. In fact, the application checks a configuration hash for allowed files, as you suggested. I had suspected that was a security feature, now I know for sure.

The base template and page templates are generally hashrefs which specify HTML::Template templates and other data, but may also run perl code.

It does look like the main executable is called by eval. My desire to run in taint mode is motivated more by my desire to catch newbie mistakes on my part, than by a distrust in the base application (though I do try to cultivate a healthy distrust by default).

Again, thanks for your help, learning opportunities like this help me build a mental framework upon which I can develop with reading on my own.


Comment on Re^2: security and un-tainting paths

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://933166]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others lurking in the Monastery: (9)
As of 2014-07-28 07:25 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    My favorite superfluous repetitious redundant duplicative phrase is:









    Results (193 votes), past polls