From: Paul Brannan Date: 2004-06-22T22:50:22+09:00 Subject: Re: Full-featured untaint() method for Ruby? On Tue, Jun 22, 2004 at 07:24:33AM +0900, Randy Lawrence wrote: > What we'd like to find out is if there is a ruby class or method that > will fully parse+modify+untaint (rather than simply removing the taint > flag) of: > > 1. strings potentially utilized as part of a shell command > (prevent shell command injection) I do not know of such a method, but I agree there should be one. > 2. strings potentially utilized as part of sql statements > (prevent sql injection) Each database library should provide a method that does this. For example, the Ruby MySQL library provides Mysql.escape_string(). > 3. strings potentially utilized as part of html documents > (prevent cross-site scripting) Use CGI.escapeHTML() or WEBrick::HTMLUtils.escape() or ERB::Util::html_escape() (or any of the others escape mechanisms provided in one of the standard libraries) for this. If you want the string to retain its html formatting but strip out scripts, you'll probably need to roll your own method. Paul