Re: Tainted Mode Decision

From: Date: Sun, 18 Nov 2007 13:24:35 +0000
Subject: Re: Tainted Mode Decision
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-33250@lists.php.net to get a copy of this message
The other difference is that Venema's implementation assumes that functions exist that make a variable safe for usage in SQL, HTML, ... When such a function is used the variable is marked as not tainted... In the previous mail I showed examples why this is not secure. GRASP on the other hand hooks the SQL/output functions and parses the SQL query/output and catches tainted bytes in places where they could be dangerous. The only problems here are how slow this is and that the parsers need to be compatible.
BTW, have you already been able to found real-world exploitable bugs with GRASP? Nuno

« previous php.internals (#33250) next »