From: Daniel Carrera Date: 2003-02-13T06:12:36+09:00 Subject: Re: mod_ruby insecury op On Thu, Feb 13, 2003 at 05:51:31AM +0900, Daniel Bretoi wrote: > Thanks guys, this one stings me every time. What exactly does untaining > on the string do? > > db If you turn on safety, any data received from outside your program is considered "tainted" (i.e. untrustworthy). Tainted data cannot be used to affect your system. It has to be untainted. Taintedness is a way to force you to take safety precautions that you might otherwise forget. In your example, suppose that you get 'dir' from a web interface. You ask the user for a directory and you do something with it. A malicious user could type: #{`rm -f *`} When you put that in your program you get "...#{`rm -f *`}...". The `rm -f *` gets called and all your files get deletted. I'm sure that you can come up with worse things that a user could do. To untaint data you use regular expressions. In this case a directory name should only be composed of "word" charcaters and the character "/". Do something like: # dir tainted. if dir =~ /^([\w\/]+)$/ dir = $1 # Untainted. else # Error... end Cheers, -- Daniel Carrera Graduate Teaching Assistant. Math Dept. University of Maryland. (301) 405-5137