Perl is the main server scripting language for web servers. It is used because of its ease of use and its power, but because of the ease of use, a power perl can be exploited. This document will tell you how to secure your web server from attacks.
Perl scripts can be identified by the outside world as they normally have .pl or .cgi extensions.
Tainting
IF you have ever seen a perl script, you will have noticed that on the first line there is the path to the perl program. eg:
#!/usr/local/bin/perl -w
The -w tells perl to give warnings if there are errors in the code. The security equivalent is to disallow insecure commands from user input. The way this works is that user input cannot execute a command, but any variable created in the script can. eg;
$input= ; STDIN is from the user, so it is considered as insecure
$untainted = "hi";
To enable this secure mode (or tainting, to call it its proper name) add -t to the line, eg; #!/usr/local/bin/perl -T or #!/usr/local/bin/perl -Tw
You can untaint a variable by putting the data it contains into a variable name $number, e.g. $input = $1; The following perl script parses user input if it doesn’t contain dangerous characters tells perl it is secure: