Re: Secure Form Script?

From: Stephen Samuel (samuel_at_bcgreen.com)
Date: 05/16/04

  • Next message: Tim Greer: "RE: Secure Form Script?"
    Date: Sun, 16 May 2004 08:21:23 -0700
    To: Glynn Clements <glynn.clements@virgin.net>
    
    

    Glynn Clements wrote:
    > Bryce Porter wrote:

    >>running as. Directly executing anything is a big risk no matter how you
    >>look at it, as far as I'm concerned.
    >
    > No. The risk isn't in *directly* executing a program; it's executing
    > it via the shell.
    ....
    > OTOH, if you pass a scalar or a single-element array, it may be passed
    > to the shell (if the string contains no shell metacharacters, perl
    > will use its own trivial shell emulation instead). Similarly,
    > backticks use the shell.
    >

    I'd further say that what's dangerous is passing a stranger-provided
    string to the shell. Passing an unsanitized stranger-provided
    string to the shell, however isn't dangerous. It would be simply
    insane.

    -- 
    Stephen Samuel +1(604)876-0426                samuel@bcgreen.com
    		   http://www.bcgreen.com/~samuel/
        Powerful committed communication. Transformation touching
          the jewel within each person and bringing it to light.
    

  • Next message: Tim Greer: "RE: Secure Form Script?"

    Relevant Pages

    • Memorial Day report
      ... the pieces I'd fused with my bare match used a double string (parallel ... My film cannister shell was a test of my first use of homemade piped ... One of the stars distinctly changed from ... I get a good fire seal and fit to the mortar without noticeably ...
      (rec.pyrotechnics)
    • Re: Off center spiking
      ... 32 - The procedure is the same for any diameter shell. ... strands of cotton, laying flat next to each other both vertically ... pick a guide mark on top and wind to the bottom matching ... shell from what appear to be two separate strands of string. ...
      (rec.pyrotechnics)
    • Re: Off center spiking
      ... Your video is worth 1000 times that. ... 32 - The procedure is the same for any diameter shell. ... strands of cotton, laying flat next to each other both vertically ... shell from what appear to be two separate strands of string. ...
      (rec.pyrotechnics)
    • comp.unix.shell FAQ - Answers to Frequently Asked Questions
      ... This FAQ list contains the answers to some Frequently Asked Questions ... It spells "unix" in lower case letters ... The other level is how to write shell scripts. ... if the string being echoed wasn't built into the script ...
      (comp.unix.shell)
    • comp.unix.shell FAQ - Answers to Frequently Asked Questions
      ... This FAQ list contains the answers to some Frequently Asked Questions ... It spells "unix" in lower case letters ... The other level is how to write shell scripts. ... if the string being echoed wasn't built into the script ...
      (comp.unix.shell)