Beefy Boxes and Bandwidth Generously Provided by pair Networks
Perl-Sensitive Sunglasses
 
PerlMonks  

Re: Re: Re: Re: Re: How to do that with eval ?

by perlmonkey (Hermit)
on Apr 10, 2004 at 19:58 UTC ( #344163=note: print w/ replies, xml ) Need Help??


in reply to Re: Re: Re: Re: How to do that with eval ?
in thread How to do that with eval ?

By 'above' I was refering to my previous post. If you run an eval on user input, the user input could be anything. In this case if the user instead of entering '>=' like we expect, enters ';`sudo rm -rf /`;' this will make the eval execute this extremely damaging command.

For more reasons of how to make sure you are not allowing users to do bad things, please read the perlsec manpage


Comment on Re: Re: Re: Re: Re: How to do that with eval ?

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://344163]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others having an uproarious good time at the Monastery: (6)
As of 2014-07-13 09:40 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    When choosing user names for websites, I prefer to use:








    Results (249 votes), past polls