Beefy Boxes and Bandwidth Generously Provided by pair Networks
laziness, impatience, and hubris

Re^2: Loading a Local File

by Corion (Pope)
on Jan 04, 2018 at 12:07 UTC ( #1206681=note: print w/replies, xml ) Need Help??

in reply to Re: Loading a Local File
in thread XML::Parser Tutorial

What you call "xml bomb" is most likely the XML Entity Expansion attack.

This is most easily prevented by not expanding entities, or not expanding them recursively.

To enable that, see the XML::Parser documentation, especially the NoExpand flag and the handlers for external and other entities.

In those, you get to decide whether to fetch them and whether to expand them. If an entity expands to more entities, consider whether to expand them or not.

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://1206681]
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others romping around the Monastery: (5)
As of 2020-09-28 15:50 GMT
Find Nodes?
    Voting Booth?
    If at first I donít succeed, I Ö

    Results (144 votes). Check out past polls.