Re: 'safe' printing to the terminal
[email protected] (Russ Allbery) Mon, 11 May 2026 09:07:05 -0700
| Newsgroups | perl.perl5.porters |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
Michiel Beijen <[email protected]> writes: > I feel 'printing of untrusted output to the terminal' is something that > should have a de-facto solution in core perl; would it be weird to want > to have a 'standard' solution for this? I think this would be a very good idea. There have been a pretty consistent stream of security reports about inadequate escaping, and most people don't realize how many weird things can be done with terminal escape sequences. I would go one step farther and would add that it would be a good idea to provide some sort of pragma that automatically escapes the output of die and warn, given how frequently untrusted data such as potentially attacker-controlled file names are embedded in those messages via string interpolation. -- #!/usr/bin/perl -- Russ Allbery, Just Another Perl Hacker $^=q;@!>~|{>krw>yn{u<$$<[~||<Juukn{=,<S~|}<Jwx}qn{<Yn{u<Qjltn{ > 0gFzD gD, 00Fz, 0,,( 0hF 0g)F/=, 0> "L$/GEIFewe{,$/ 0C$~> "@=,m,|,(e 0.), 01,pnn,y{ rw} >;,$0=q,$,,($_=$^)=~y,$/ C-~><@=\n\r,-~$:-u/ #y,d,s,(\$.),$1,gee,print