Untrustworthy Sources of Data
Command-line arguments
Anything read from filehandle/socket
Filenames - from readdir(), glob(), readlink()
Environment variables (incl: CGI)
Locale information
User info - getpwxxxx()
etc
Wellington Perl Mongers
13 November 2007