--stein
--stein
Back at Rick's conference in 2005, I presented some ideas about protecting backdoor maintenance/admin features that required eval/macro of user-supplied expressions. The idea was simple--a whitelist of allowed functions and methods using (I think) RegEx.
I never took that idea anywhere, but now the need has resurfaced. If anyone has notes from that session (not sure the topic was formal), or better, has actually put it into practice and wants to share back, please either post here (or contact me if you can't).
Thanks.
Randy