Re: Testing for the '..' directory in access handlers... (directory testing 101)

2000-01-16 Thread Gunther Birznieks
It may be worth mentioning that a recent expose' on bad CGI scripts by Rain Forest Puppy in Prack issue #55 revealed that some system calls take backslashes and use them to escape dots, so its useful to get into the habit of also checking for optionally backslashed periods in a row instead of jus

Re: Testing for the '..' directory in access handlers... (directory testing 101)

2000-01-16 Thread Randal L. Schwartz
> "Sean" == Sean Chittenden <[EMAIL PROTECTED]> writes: Sean> Hey. So I just went through and was auditing someone's code today Sean> (the joy of joys that it is) and these guys were pretty reliant on their Sean> access, authen, authz handlers for most everything related to their site Sean