3 ms·
This is horrible advice. If you don't check input for correctness at all, an attacker could inject all kinds of nastyness into am underlying system, which may e
by janosd 4y ago
This is horrible advice. If you don't check input for correctness at all, an attacker could inject all kinds of nastyness into am underlying system, which may expose bugs.
For example, control characters, line breaks, shell escape characters, SQL injections, or simply uploading an ISO image into the E-mail field.
There is the RFC, and there is what we would nowadays consider a sane E-mail address. Nobody has addresses with spaces, nor does anyone have an address with an IP literal in it. Why? Because no other system will accept it. Think bank, etc.
TL;DR at the very least you need to validate field length, control characters, quote signs, and backslashes. Those have no business being in am e-mail address.
- threeys 4y ago