From what I understand, there was temporarily a note here from a fellow monk about how I had doubled the damage by revealing specifics.
Please let me assure you that the code snippet I posted
by deliberate action:
- Did not mention the name of the client
- Changed the name of the parameter
- Changed the eval-ish code
Yes, a correlation between the timing of my rant and
my public schedule does indeed reveal that this is a $VERY_LARGE_COMPANY in Silicon Valley. I'll grant that
as a leak. But the web search suggested to me in the
message box revealed only a handful of companies, none
of which is $VERY_LARGE_COMPANY.
Please give me a little credit here. I'm not willing to
compromise my customer's security (even if they've
already done it themselves). I'm just pointing out the
sad state of web security in the world, and being afraid
for my own transactions as I continue to shop and bank
and share information on-line. And hoping maybe I can
stir some of you up to take on security with a bit more vigor, or know when to call in the experts if you don't
see why having eval and fatalsToBrowser were both compoundingly bad news there.
-- Randal L. Schwartz, Perl hacker
Posts are HTML formatted. Put <p> </p> tags around your paragraphs. Put <code> </code> tags around your code and data!
Read Where should I post X? if you're not absolutely sure you're posting in the right place.
Please read these before you post! —
Posts may use any of the Perl Monks Approved HTML tags:
You may need to use entities for some characters, as follows. (Exception: Within code tags, you can put the characters literally.)
- a, abbr, b, big, blockquote, br, caption, center, col, colgroup, dd, del, div, dl, dt, em, font, h1, h2, h3, h4, h5, h6, hr, i, ins, li, ol, p, pre, readmore, small, span, spoiler, strike, strong, sub, sup, table, tbody, td, tfoot, th, thead, tr, tt, u, ul, wbr
Link using PerlMonks shortcuts! What shortcuts can I use for linking?
See Writeup Formatting Tips and other pages linked from there for more info.
| & || & |
| < || < |
| > || > |
| [ || [ |
| ] || ] ||