Beefy Boxes and Bandwidth Generously Provided by pair Networks
Come for the quick hacks, stay for the epiphanies.
 
PerlMonks  

Re^14: Making Perl Monks a better place for newbies (and others)

by PerlGuy(Tom) (Acolyte)
on Feb 06, 2020 at 17:12 UTC ( [id://11112505]=note: print w/replies, xml ) Need Help??


in reply to Re^13: Making Perl Monks a better place for newbies (and others)
in thread Making Perl Monks a better place for newbies (and others)

This node falls below the community's threshold of quality. You may see it by logging in.
  • Comment on Re^14: Making Perl Monks a better place for newbies (and others)

Replies are listed 'Best First'.
Re^15: Making Perl Monks a better place for newbies (and others)
by haukex (Archbishop) on Feb 06, 2020 at 17:49 UTC
    Can't then any hacker, or even someone accidently, POST literally any code whatsoever?

    This website has been around for a long time, and many of the greatest Perl hackers of all time have passed through these halls. Do you really think no one here knows about Bobby Tables? And I believe you were linked to Markup in the Monastery already, did you take the time to look at that? Or perhaps tried to post some <script> tags yourself to see whether XSS attacks are even possible?

    If you want to show that you're here to help and improve things, I would suggest you start looking at the codebase, which you've been given access to. Otherwise, people are going to lose patience and start assuming you're just trolling.

      > Otherwise, people are going to lose patience and start assuming you're just trolling.

      Duck typing tells me somewhere between Dunning-Kruger Effect and natural born trolling.

      Doesn't matter where exactly in between because both are valid reasons to stop feeding.

      Though impressive how fast you can become pmdev without proving any expertise or even knowledge of the site ...

      Cheers Rolf
      (addicted to the Perl Programming Language :)
      Wikisyntax for the Monastery FootballPerl is like chess, only without the dice

        impressive how fast you can become pmdev without proving any expertise or even knowledge of the site

        Hopefully this shows my confidence in how safe it is to have random monks looking at the code.

Re^15: Making Perl Monks a better place for newbies (and others)
by Your Mother (Archbishop) on Feb 06, 2020 at 17:39 UTC
    don't trust user input

    That is absolutely correct. All the assumptions and conclusions you’re piling on top of it are not. <script src="//hax0r.cx/pwnd.js"></script> can sit as is in the database just fine, as can Tye');DROP TABLE Monks;-- and any other content treated properly going in and coming back out.

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://11112505]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others cooling their heels in the Monastery: (6)
As of 2024-04-23 19:28 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found