[4330] in WWW Security List Archive
Re: Perl System Call HACKS
daemon@ATHENA.MIT.EDU (Brian W. Spolarich)
Mon Feb 10 19:21:58 1997
Date: Mon, 10 Feb 1997 16:49:09 -0500 (EST)
From: "Brian W. Spolarich" <briansp@ans.net>
To: Jeff Middleton <jeffm@sgiserv3.aws.waii.com>
cc: www-security@ns2.rutgers.edu
In-Reply-To: <9702100746.ZM23110@sgiserv3.aws.waii.com>
Errors-To: owner-www-security@ns2.rutgers.edu
On Mon, 10 Feb 1997, Jeff Middleton wrote:
| Is there a FAQ or information giving some examples as to the way
| a perl script that executes sendmail via a PERL system call can
| be hacked?
I'd start with the WWW Security FAQ
http://www-genome.wi.mit.edu/WWW/faqs/www-security-faq.html
especially sections 6 (CGI scripts) and 7 (Safe Scripting in Perl).
-brian
--
Brian W. Spolarich - ANS Systems Development - briansp@ans.net - 313-677-7311
At the sight of Nothing the Soul rejoices. -- Thomas Moore