Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Preventing cross site scripting

From: Andrew Beverley <andy(at)andybev.com>
Date: Tue Jun 24 2003 - 16:52:19 EDT

Hi,

Just a quick note to say thanks to all the people who have come up with a wealth of different solutions to this problem. It seems to me as if the best solution is to htmlentities() (or similar) the whole lot, then only convert back what you know.

It's good to see that there are projects around trying to deal effectively with XSS. What would be brilliant would be if languages such as php included a builtin function for this. Not only would it make it dead easy, but also, as html standards change over time, the function would presumably be updated in future versions, and then by simply keeping an up to date copy of php (which presumably you would do anyway), your XSS filtering keeps up to date.

Thanks,

Andrew Beverley

Andrew Beverley wrote:

> I am currently writing a web application that, as a small part of it,
Received on Tue Jun 24 17:07:38 2003

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:53 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library