NYCPHP Meetup

NYPHP.org

[nycphp-talk] worm/virus's hammering feedback scripts? POLISHED VERSION

David Mintz dmintz at davidmintz.org
Wed Sep 14 15:29:19 EDT 2005


On Tue, 13 Sep 2005, inforequest wrote:

> [....]
> Thanks for the enlightening discussion.
>
> While I agree completely with pro-active judging of input data, there
> are cases where users cut-n-paste data into form fields (from Word, for
> example) and inadvertently transfer all sorts of garbage (including
> CR/LF stuff).

How about this: if you are expecting single-line input such as a last
name, first trim() it, then test it for embedded CR/LF

---
David Mintz
http://davidmintz.org/



More information about the talk mailing list