[ale] OT - looking for some guidance with a perl script

F. Grant Robertson f.g.robertson at alexiongroup.com
Mon Apr 21 08:56:49 EDT 2003


I suppose they might be able to escape it in some way.. probably with % notation..  I think that gets converted by cgi anyway though.  <shrug>  Fletch? Where are you?

And you know, now that I think of it, there may be a cpan module for securing paths.. might be worth a look.  http://search.cpan.org/

-Grant


-----Original Message-----
From: ale-admin at ale.org [mailto:ale-admin at ale.org]On Behalf Of Jim Lynch
To: ale at ale.org
Sent: Monday, April 21, 2003 8:49 AM
To: ale at ale.org
Subject: Re: [ale] OT - looking for some guidance with a perl script


That would work, but I wasn't absolutely sure that would be secure
enough.  I figured someone might find a way to work around that.  I
can't but I've lived long enough to know that isn't much of a test.  8)

Thanks,
Jim.

"F. Grant Robertson" wrote:
> 
> Jim,
> A regexp would probably be good enough..
> 
> $path =~ s/..\///sg;
> 
> something like that, you could refine it for your particular level of paranoia..
> 
> Someone will probably have a better answer but, that's how I'd handle it
> 
> -G
> 
> "No, I don't think your paranoid, just the opposite. I think you have these insane delusions that everyone really likes you." - Woody Allen
_______________________________________________
Ale mailing list
Ale at ale.org
http://www.ale.org/mailman/listinfo/ale


---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.474 / Virus Database: 272 - Release Date: 4/18/2003

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.474 / Virus Database: 272 - Release Date: 4/18/2003

_______________________________________________
Ale mailing list
Ale at ale.org
http://www.ale.org/mailman/listinfo/ale





More information about the Ale mailing list