OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Exploit-Dev Archives: Re: Guestbook perl script (error fix)

Re: Guestbook perl script (error fix)


Vincent Zweije (zweijeXS4ALL.NL)
Sat, 9 Oct 1999 13:54:32 +0200


Matt Carothers:

|| The entire "<!--#" has to be there to trigger a directive handler. Removing
|| all occurances of "<!--#" from the input is sufficient to neuter all
|| server-side includes.
||
|| $value =~ s/<!--#//g;

I suspect that will fail for:

    <!--<!--##

Ciao. Vincent.



This archive was generated by hypermail 2.0b3 on Mon Oct 11 1999 - 19:59:49 CDT