Beefy Boxes and Bandwidth Generously Provided by pair Networks
There's more than one way to do things

Re: Vetting a CGI script

by hardburn (Abbot)
on Nov 12, 2003 at 17:37 UTC ( #306565=note: print w/replies, xml ) Need Help??

in reply to Vetting a CGI script

It should reset $ENV{PATH} (which taint mode will force you to do anyway).

You will need to escape any pipe characters in the data from the client before it is printed to the file.

I suggest always using the three-element form of open that was made available in perl 5.6.0, though in this case it's not a big deal.

If you happen to be printing any user input in the e-mail headers, be sure to be very strict about what is allowed into them. About a month ago, we caught a spammer using one of our CGIs. The trick used was to put a new line in the to field followed by To:, which was interpolated into the e-mail header. This would have allowed any address to be spammed, but the CGI appended our own domain name to the to field before sending, so all that happend was a lot of bounces. This made our e-mail admin very grumpy until we ran more strict validation on the fields, but it could have been worse. There were other fields that the spammer could have used that were also placed directly into the headers that didn't have anything appended to them. We are fortunate that the spammer wasn't quite that smart.

I wanted to explore how Perl's closures can be manipulated, and ended up creating an object system by accident.
-- Schemer

: () { :|:& };:

Note: All code is untested, unless otherwise stated

Replies are listed 'Best First'.
Re: Re: Vetting a CGI script
by dvergin (Monsignor) on Nov 12, 2003 at 18:03 UTC
    In this case all the email header data is hard-coded in the script. Can anything bad be done with external data that is piped to sendmail for the body (after the "\n\n" that follows the header)?

    "Perl is a mess and that's good because the
    problem space is also a mess.
    " - Larry Wall

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://306565]
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others wandering the Monastery: (6)
As of 2021-01-25 10:24 GMT
Find Nodes?
    Voting Booth?