Re: Preventing XSS in PHP...

From: alrferreiraat_private
Date: Fri May 03 2002 - 09:37:31 PDT

  • Next message: Sebastian: "Re: static char overflow"

    >Yep...some even say "too much" and argue that it isn't
    >
    >a "real security hole", but if you've had your admin cookie
    >stolen on a forum then you would say otherwise.
    >
    >yep PHP can handle input sanitizing very well...hopefully
    >
    >all new webApp langs will have sanitizing functionality
    >
    >built into their frameworks...(MS actually does in asp.net)
    >
    >I suggest you check out the webAppSec list, the OWASP
    >
    >project, and cgisecurity.com for more info.
    >
    >http://online.securityfocus.com/archive/107
    >
    >http://www.owasp.org
    >
    >http://www.cgisecurity.com
    >
    >Take care,
    
    That is really interesting... Somebody would have more information on as to
    implement this in ASP?
    Without having that to filter all manually tags?
    
    Thanks...
    
    André Luiz Rodrigues Ferreira
    



    This archive was generated by hypermail 2b30 : Fri May 03 2002 - 11:09:49 PDT