Beefy Boxes and Bandwidth Generously Provided by pair Networks
Keep It Simple, Stupid

Re: Icky Gross and Disgusting @INC Kludges. (code, discussion)

by mikfire (Deacon)
on May 14, 2001 at 20:49 UTC ( #80254=note: print w/replies, xml ) Need Help??

in reply to Icky Gross and Disgusting @INC Kludges. (code, discussion)

In approximately the order they were asked
  1. You really can't - sooner or later the web daemon has to read the files and any sufficiently capable blackhat can read them. The best solution I found was a directory where the webdaemon can read and you can write. This at least stops blackhats from reading *your* directory.
  2. I do not think ( and I am sure merlyn will correct me on this ) it is *that* much of a security risk. I would be far more concerned about bad input than about a blackhat discovering what modules I am using.
  3. Don't know :)
  4. First, only pure-perl modules will work - anything using XS is right out. Second, you need to make sure the modules are not using perl 5.6 specific widgets. Given those two conditions, things should just work. Personally, I wouldn't do it. I bet things would fail in spectacular fashions when one of the two conditions is not met.
  5. See previous
  6. Bribery. Speaking as an admin myself, bribery almost always works. Offer to buy the sysadmin a cup'a'joe/ soda/lunch, whatever. Let the SA know that you would like this as a personal favour. Mention that this would not involve breaking existing scripts - perl 5.6 could be installed in a completely different path. Tell your SA that you don't mind doing the compile/test phase. Tell your SA you will do the postinstall work as well. Mention that perl 5.6.1 is out ( the magic first revision ). More bribery. Begging rarely works, but it does sometimes amuse me :)
  • Comment on Re: Icky Gross and Disgusting @INC Kludges. (code, discussion)

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://80254]
and all is quiet...

How do I use this? | Other CB clients
Other Users?
Others studying the Monastery: (5)
As of 2018-06-20 23:25 GMT
Find Nodes?
    Voting Booth?
    Should cpanminus be part of the standard Perl release?

    Results (117 votes). Check out past polls.