Beefy Boxes and Bandwidth Generously Provided by pair Networks
Welcome to the Monastery

comment on

( #3333=superdoc: print w/replies, xml ) Need Help??
Yes Perl is vulnerable as almost every computer language.
(Race condition,NULL poison...)
But Perl has some feature that you could use to greatly reduce the risks :
  • Suidperl
  • The Taint mode
  • The automatic memory allocation
  • Modified (s)printf (no format string attack..)
  • Tons of open sourced robust security tools/modules : For encrypting, signing, communicating...

Perl provides you many tools to produce safe code, but also enough freedom to screw your security...

Anyway, to my mind, the security shouldn't be enforced by the language but by the programmer.
You should better watch carefully your code logic to ensure security
(this combined with a decent OS (which excludes windows ;-) should provide enough security)

Don't hesitate to use Super Search with 'security' as keyword to find tons of interesting threads...
Perlsec and the Camel's chapter about security should be mandatory too...

"Only Bad Coders Code Badly In Perl" (OBC2BIP)

In reply to Perl is a secure language (as far as it can be) by arhuman
in thread Secrets & Lies & Perl by ichimunki

Use:  <p> text here (a paragraph) </p>
and:  <code> code here </code>
to format your post; it's "PerlMonks-approved HTML":

  • Are you posting in the right place? Check out Where do I post X? to know for sure.
  • Posts may use any of the Perl Monks Approved HTML tags. Currently these include the following:
    <code> <a> <b> <big> <blockquote> <br /> <dd> <dl> <dt> <em> <font> <h1> <h2> <h3> <h4> <h5> <h6> <hr /> <i> <li> <nbsp> <ol> <p> <small> <strike> <strong> <sub> <sup> <table> <td> <th> <tr> <tt> <u> <ul>
  • Snippets of code should be wrapped in <code> tags not <pre> tags. In fact, <pre> tags should generally be avoided. If they must be used, extreme care should be taken to ensure that their contents do not have long lines (<70 chars), in order to prevent horizontal scrolling (and possible janitor intervention).
  • Want more info? How to link or How to display code and escape characters are good places to start.
Log In?

What's my password?
Create A New User
Domain Nodelet?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others making s'mores by the fire in the courtyard of the Monastery: (7)
As of 2023-02-06 10:06 GMT
Find Nodes?
    Voting Booth?
    I prefer not to run the latest version of Perl because:

    Results (33 votes). Check out past polls.