Quantcast
Channel: West Wind Message Board Messages
Viewing all articles
Browse latest Browse all 10393

Re: WhiteList Functions and Methods

$
0
0
Re: WhiteList Functions and Methods
Security
Re: WhiteList Functions and Methods
05/14/2012
07:43:35 AM
3I30GK80S Show this entire thread in new window
Gratar Image based on email address
From:
Stein Goering
To:
Attachments:
None
Finally got around to digging thru my archived docs - I was at that conference but unfortunately can't find any notes on your session. Too bad for me because since then I ended up cobbling together some rather ugly code to accomplish the same thing in my apps - I'm sure I'd have something more maintainable if I'd started with what you presented. What I've got is not really worth sharing, as I recall it uses a hardcoded whitelist and some ATC calls.

--stein


Hi all,

Back at Rick's conference in 2005, I presented some ideas about protecting backdoor maintenance/admin features that required eval/macro of user-supplied expressions. The idea was simple--a whitelist of allowed functions and methods using (I think) RegEx.

I never took that idea anywhere, but now the need has resurfaced. If anyone has notes from that session (not sure the topic was formal), or better, has actually put it into practice and wants to share back, please either post here (or contact me if you can't).

Thanks.

Randy


Viewing all articles
Browse latest Browse all 10393

Trending Articles