Uploaded image for project: 'Gateway'
  1. Gateway
  2. GTWY-145

Sanitize User Input for Cross Site Scripting Attacks

XMLWordPrintable

    • Icon: Defect Defect
    • Resolution: Cannot Reproduce
    • Icon: Major Major
    • Recycle Bin
    • None
    • Security
    • None

      Jeff Atwood wrote a nice blog article on Cross Site Scripting (XSS) attacks.

      http://www.codinghorror.com/blog/archives/001167.html

      It give recommendations on how to avoid accedently allowing users to insert malicous java scripts into our applicaiton.

      I also think using Bulletin Board Code (BBCode) would still be fairly effective too.

      Here is another link that explains in detail how XSS attacks work:
      http://en.wikipedia.org/wiki/Cross-site_scripting

              Unassigned Unassigned
              nhook Nathan Hook
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: