Re: yaml/xml/json, POST data, bloodcurdling terror

From: Eric Lease Morgan <emorgan_at_nyob>
Date: Thu, 17 Dec 2015 15:25:36 -0600
To: CODE4LIB_at_LISTSERV.ND.EDU
On Dec 17, 2015, at 8:22 AM, Andromeda Yelton <andromeda.yelton_at_GMAIL.COM> wrote:

> I strongly recommend this hilarious, terrifying PyCon talk about
> vulnerabilities in yaml, xml, and json processing:
> 
>   https://www.youtube.com/watch?v=kjZHjvrAS74
> 
> If you process user-submitted data in these formats and don't yet know why
> you should be flatly terrified, please watch this ASAP; it's illuminating.
> If you *do* know why you should be terrified, watch it anyway and giggle
> along in knowing recognition, because the talk is really very funny.


Obviously, the sorts of things outlined in the presentation above are real, and they are really scary. Us developers need to take note: getting input from the ‘Net can be a really bad thing. —Eric Lease Morgan
Received on Thu Dec 17 2015 - 16:26:07 EST