Posted Dec 9, 2009 3:56 UTC (Wed) by pjm (subscriber, #2080)
[Link]
That would be a blacklist approach. The whole point of cesarb's comment is that one would usually prefer a whitelist approach: create a new environment containing just PATH (with a known safe value), HOME, and a couple of others.