Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: RE: How to handle "special characters"

RE: How to handle "special characters"

From: <riptide_at_idle.curiosity.org>
Date: Thu, 11 Dec 2003 14:31:47 -0600 (CST)

There truthfully isn't a clear guidline and killer hacks are found daily.
Your application should filter
out any control, escape characters. Look for anything with a suspicious
pattern ie (../..) Stick within the ascii range with numbers and
letters.
good luck

 On Thu, 11 Dec 2003, sparkes wrote:

> On Wed, 2003-12-10 at 16:55, Tony Langley wrote:
> <snip>
> > 1) Which chars are always safe (if there are any).
> there aren't
> > 2) Which chars are always dangerous.
> those entered by the user
> > 3) Those which are sometimes one or the other.
> everything else
>
> sorry to be pessamistic but this is the only truth you need to know to
> stay safe
>
> sparkes
>
Received on Dec 12 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos