There truthfully isn't a clear guidline and killer hacks are found daily.
Your application should filter
out any control, escape characters. Look for anything with a suspicious
pattern ie (../..) Stick within the ascii range with numbers and
letters.
good luck
On Thu, 11 Dec 2003, sparkes wrote:
> On Wed, 2003-12-10 at 16:55, Tony Langley wrote:
> <snip>
> > 1) Which chars are always safe (if there are any).
> there aren't
> > 2) Which chars are always dangerous.
> those entered by the user
> > 3) Those which are sometimes one or the other.
> everything else
>
> sorry to be pessamistic but this is the only truth you need to know to
> stay safe
>
> sparkes
>
Received on Dec 12 2003