Beefy Boxes and Bandwidth Generously Provided by pair Networks
"be consistent"
 
PerlMonks  

Re: Best Module for Cross-Site Scripting ?

by pemungkah (Priest)
on Aug 18, 2010 at 22:23 UTC ( #855923=note: print w/ replies, xml ) Need Help??


in reply to Best Module for Cross-Site Scripting ?

You should make sure whatever solution you finally end up choosing can beat the XSS Cheat Sheet. That will require testing in a lot of different browsers on a lot of different machines.

You should also seriously ask these questions:

  1. Do the users really need any markup at all?
  2. If they do, does it have to be HTML?
  3. If they do, can it be a very limited set of tags?
You may find that you'll be able to choose a simpler means of filtering depending on your answers.


Comment on Re: Best Module for Cross-Site Scripting ?

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://855923]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others surveying the Monastery: (9)
As of 2015-07-30 21:46 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    The top three priorities of my open tasks are (in descending order of likelihood to be worked on) ...









    Results (273 votes), past polls