Beefy Boxes and Bandwidth Generously Provided by pair Networks
Keep It Simple, Stupid
 
PerlMonks  

Re: Best Module for Cross-Site Scripting ?

by pemungkah (Priest)
on Aug 18, 2010 at 22:23 UTC ( #855923=note: print w/replies, xml ) Need Help??


in reply to Best Module for Cross-Site Scripting ?

You should make sure whatever solution you finally end up choosing can beat the XSS Cheat Sheet. That will require testing in a lot of different browsers on a lot of different machines.

You should also seriously ask these questions:

  1. Do the users really need any markup at all?
  2. If they do, does it have to be HTML?
  3. If they do, can it be a very limited set of tags?
You may find that you'll be able to choose a simpler means of filtering depending on your answers.
  • Comment on Re: Best Module for Cross-Site Scripting ?

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://855923]
help
Chatterbox?
and all is quiet...

How do I use this? | Other CB clients
Other Users?
Others drinking their drinks and smoking their pipes about the Monastery: (8)
As of 2017-02-20 14:49 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?
    Before electricity was invented, what was the Electric Eel called?






    Results (297 votes). Check out past polls.