Your skill will accomplish what the force of many cannot |
|
PerlMonks |
Re^3: The importance of avoiding the shellby petdance (Parson) |
on Oct 01, 2014 at 19:50 UTC ( [id://1102581]=note: print w/replies, xml ) | Need Help?? |
No, I am not making any claims about taint mode mitigating the bash bug.
My point is that the bash bug is, at its core, about treating untrusted data as executable code. Perl's taint mode is designed to catch that problem in Perl code. Say you get an argument from the command line in your Perl program. That variable is now tainted, because it came from an untrusted source. Now, say you try to execute a command with system using that variable. Perl's taint mode will disallow it because the data fed to system is untrustworthy.
xoxo,
In Section
Meditations
|
|