Perl

This page should collect together any resources relating to Perl and OWASP or security in general.

It is perhaps odd that this page is so new:


 * 1) Perl has long been an open source language and often associated with the internet.
 * 2) It offers what seems to be a much under-used method of combating many sorts of exploit namely taint mode. This forces every "input" to the program to be checked for malign influences before it is allowed to effect the "outside" of the program.

Possible perl OWASP projects

 * 1) Perl ports of multi-language OWASP projects, for example AntiSamy.
 * 2) Review of CPAN modules according to OWASP standards, for example CGI::Application::Plugin::Authentication.
 * 3) A perl module to measure the strength of passwords.

Perl resources

 * 1) OWASP ESAPI Perl Project has been started.
 * 2) Perl security man page
 * 3) Perl Monks
 * 4) Security Issues in Perl Scripts by Jordan Dimov

Perl modules
An attempt to list and classify perl modules related to web security. This should lead on to discussion of vulnerabilities.

Web frameworks
Authentication modules will often be framework specific so let's list those.

Authentication
A lot of generic authentication modules can be found on CPAN.

Also HTTPD::User::Manage.

Authorization
I am not aware of anything generic.

HTML validation/cleanup
Anything similar to AntiSamy should go here.

HTML::Scrubber

HTML::Tidy5

There is a discussion on this subject going on at PerlMonks:Dynamic HTML cleanup.

Password strength
Data::Password::Entropy

Data::Password::zxcvbn a port of Dropbox’s JavaScript implementation.

CAPTCHA alternatives
These are attempts to distinguish human and robot users. CAPTCHA is not perfect at this and is highly inaccessible.

Authen::Quiz

Dancer::Plugin::reCAPTCHA Mojolicious::Plugin::Recaptcha