Beefy Boxes and Bandwidth Generously Provided by pair Networks
There's more than one way to do things
 
PerlMonks  

Re: Re: Re: Quotes In CGI

by jlongino (Parson)
on Oct 08, 2002 at 03:37 UTC ( #203567=note: print w/replies, xml ) Need Help??


in reply to Re: Re: Quotes In CGI
in thread Quotes In CGI

You are correct, although your example would not work as you intended, something along the lines of the following would:
script.cgi?x=' . system "any valid OS command here" . '
the eval of which would look like this:
$x = '' . system "any valid OS command here" . '';
In this particular case, the UnTaint would not find any "naughty" symbols we associate with usual system cracking attempts. My focus, however was to address the cause of the poster's immediate problem. The references to the other links and the warning I think were sufficient. In his CGI Course, Ovid addresses these and other security issues.

--Jim

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://203567]
help
Chatterbox?
[marioroy]: choroba++, Discipulus++. It depends on the type of module. Data-type "only" modules are likely multi-process safe, re: Hash::Ordered, Tie::IxHash.
[marioroy]: ... when shared via MCE::Share-> share(...)
[marioroy]: Net type modules are likely not multi-process safe unless stated in the documentation.
[marioroy]: The Prima author fixed his module to be both thread and multi-process safe. Thanks Dmitry.
[marioroy]: Of all the GUI-type modules, Prima was the worst regarding thread/multi- process safety. Now, it's the best for safety. ;-)
[marioroy]: Tk, Gtk2, Gtk3 requires extra care.

How do I use this? | Other CB clients
Other Users?
Others contemplating the Monastery: (8)
As of 2017-09-22 10:13 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?
    During the recent solar eclipse, I:









    Results (260 votes). Check out past polls.

    Notices?