develooper Front page | perl.beginners | Postings from February 2002

RE: Allow only letters and numbers?

Thread Previous | Thread Next
Timothy Johnson
February 21, 2002 20:04
RE: Allow only letters and numbers?
Message ID:

Okay, I get what you're saying about \z, sort of, assuming that the user
doesn't have to enter in the text at a prompt and you're not reading from a
file where lines are delimited by newlines, but I don't get where this ties
into security.  Could you explain?

-----Original Message-----
From: Randal L. Schwartz []
Sent: Thursday, February 21, 2002 7:50 PM
To:; Timothy Johnson; Jeff 'japhy' Pinyan
Subject: Re: Allow only letters and numbers?

>>>>> "Timothy" == Timothy Johnson <> writes:

Timothy> If you don't mind having underscores in your text, you could also
do this:

Timothy> if($string !~ /^\w+$/){  #If the string does not have only letters,
Timothy> and underscores from start to finish (\w)

Nope, that also permits "fred\n".  Remember that $ is the same as /\n?\z/.
You want \z instead.

Very common mistake, and could have drastic effects on security.

Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095
<> <URL:>
Perl/Unix/security consulting, Technical writing, Comedy, etc. etc.
See for onsite and open-enrollment Perl

To unsubscribe, e-mail:
For additional commands, e-mail:

This email may contain confidential and privileged 
material for the sole use of the intended recipient. 
If you are not the intended recipient, please contact 
the sender and delete all copies.

Thread Previous | Thread Next Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at | Group listing | About