3 ms·
I wasn't around for this fiasco, what exactly was it?
by plttn 9y ago
I wasn't around for this fiasco, what exactly was it?
- avian 9y agoCheck the “Perl jam” series of talks given at CCC. They are quite inflammatory, but the author does have a few good points. Specifically, he shows that one of the examples in the documentation for the CGI.pm module had an exploitable vulnerability.
- chromatic 9y agoSpecifically, he shows that one of the examples in the documentation for the CGI.pm module had an exploitable vulnerability. I think that's overstating things. He reported a "vulnerability" in Bugzilla which wasn't a security problem in Bugzilla because Bugzilla uses taint, which didn't do any database injection like he claimed, and which is unrelated to CGI.pm becaues Bugzilla doesn't use CGI.pm: https://bugzilla.mozilla.org/show_bug.cgi?id=1230932 https://bugzilla.mozilla.org/show_bug.cgi?id=1230932 Furthermore, the examples in his presentation don't actually work, he relies on ignorance of lists and Perl data structures, and the one potentially interesting point he makes about calling functions in list context in hash initializers has been documented well understood as a potential mishap in web applications since 2000: https://events.ccc.de/congress/2014/Fahrplan/system/attachments/2542/original/the-perl-jam-netanel-rubin-31c3.pdf https://events.ccc.de/congress/2014/Fahrplan/system/attachme... His presentation may have some value to someone spending their first week with Perl in a web context, but that person would have to wade through a lot of nonsense to get at that value.