[EMAIL PROTECTED] writes:
> >>>>> "Han-Wen" == Han-Wen Nienhuys <[EMAIL PROTECTED]> writes:
>
> Han-Wen> Any version that uses TeX do output has lots of holes.
> Han-Wen> You can do
>
> Han-Wen> \header{ bla = "}\input /etc/passwd \def\bla{" }
>
> Han-Wen> to get /etc/passwd into the output.
>
> ok, i've disallowed the string "\input". are there any other ways a
> tex file can reach out to its environment?
there is no way to make this fool proof.
\def\bla{put}\csname in\bla\endcsname
doesn't match your grep, while it has the same eeffect
--
Han-Wen Nienhuys, [EMAIL PROTECTED] ** GNU LilyPond - The Music Typesetter
http://www.cs.uu.nl/people/hanwen/lilypond/index.html