That's why *read-eval* should IMHO default to false. Anybody knows the 
reason why it doesn't?

On Saturday, July 23, 2011 10:35:40 AM UTC+2, Mark Derricutt wrote:
>
> ...and immediately a new attack vector is born with Clojure structure 
> injection attacks...
>
> I so hope people don't start passing executable clojure back and forth.
>
> On 23/07/2011, at 7:54 PM, Jozef Wagner wrote:
>
> Clojure can run on top of JVM, CLR and Javascript VM. Clojure data 
> structures can replace syntax of SQL result sets, JSON, XML, HTML, CSS and 
> other languages (e.g. .properties syntax). Clojure data structures are even 
> used for application configuration (lein, cake).
>
>
>

-- 
You received this message because you are subscribed to the Google
Groups "Clojure" group.
To post to this group, send email to [email protected]
Note that posts from new members are moderated - please be patient with your 
first post.
To unsubscribe from this group, send email to
[email protected]
For more options, visit this group at
http://groups.google.com/group/clojure?hl=en

Reply via email to