• Hi @pbala857293 (Community Member)​,

     

    I would recommend against calling `open()` with 2 parameters and, instead, use the better 3 parameter way (for more information on this, you may want to check out this: https://perlmaven.com/open-files-in-the-old-way). By doing this, you ensure that the operation mode is hardcoded and cannot be tampered with. This also prevents potential attack vectors aiming to append OS commands to the filename e.g. via semicolons. Using the 3 parameter way (e.g. `open my $in, '>', $filename or die ...;`) is the most effective measure against OS Command Injection attacks via `open()`.

     

    Furthermore, I would recommend providing input validation on `$new_file`. As an example, you could split it into filename and file extension, validate the file extensions against an allow-list of allowed extensions and make sure that the filename is alphanumeric (if applicable to your use case). On top of that, I would recommend using the File API to check if the file to access actually exists.

     

    Thank you,

    Florian Walter

    Expand Post

Topics (5)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.