Securing CGI scripts

I am working on a site based on the module which will allow a large amount of user interaction. What are some techniques for securing against hackers? Are there any good reasources on the web or in print that I should read?


    The Essential CGI Security Practices thread gives a good overview of... Essential CGI Security Practices ;-). Make sure to read all the replies in the thread as well.

    I do like a lot of the online resources, including Ovid's tutorial, but sometimes I'm really pedantic and like to have an actual book in front of me.

    I'd recommend CGI Programming with Perl, 2nd Ed from O'reilly (please forgive me, but I can't remember the author ATM). Chapter 9 is about security, including taint checking with -T. It also gives some great general advice, and demonstrates various styles of creating your CGI scripts (such as using the CGI module via a functional or OOP style interface, or having CGI generate your HTML versus using a here doc)

    One of the more simple tricks, of the base security features is running perl with the -T switch (which means perlTaint on.) This forces you to have your programs review all input, whenever it is going to do something (d/r)isky ;^)

