Re: Preventing XSS in PHP...

From: Slow2Show (sl2shoat_private)
Date: Fri May 03 2002 - 11:47:57 PDT

  • Next message: Paolo Iorio: "Re: BACKSTEALTH reverse engineered"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <OFE256DE49.2B105DB6-ON03256BAE.005150E7at_private>
    
    >That is really interesting... Somebody would have more
    >information on a
    >s to
    >implement this in ASP?
    >Without having that to filter all manually tags?
    
    I think you misunderstood me, the asp.net framework has 
    validation controls such as asp:RangeValidator and 
    asp:RequiredFieldValidator available to the webApp 
    developer…just like PHP has functions such as 
    HTMLSpecialChars
    There is no "universal form input sanitizing"
    
    Some articles and examples:
    
    http://www.eraserver.net/robertlair/example_validators.aspx
    http://www.aspalliance.com/chrisg/default.asp?article=59
    http://msdn.microsoft.com/library/en-
    us/dnaspp/html/pdc_userinput.asp
    
    Ciao,
    
    -Slow2Show-
    University of Florida
    



    This archive was generated by hypermail 2b30 : Fri May 03 2002 - 16:56:02 PDT