Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: AppSec FAQ at OWASP

Re: AppSec FAQ at OWASP

From: Laurian Gridinoc <laur_at_gd.ro>
Date: Fri, 30 Jan 2004 06:37:06 -0000

> I would like to know that how you deal with the false positive?
> In the case of " <img src= "javascript: preview(....)> or <img
> src="javascript:window.close()>..etc..etc..
> If you escape the "(" and ")" that means you render out the harmless
> Javascript too.
> Omarjan Ismail

I would say that using unregistered schemes as 'javascript:' in 'src' or
'href' attributes is bad design.
If you want to bind javascript to an element, use events.

Cheers,

Laurian Gridinoc
Chief Developer
GRAPEFRUIT DESIGN
www.grapefruitdesign.com
Received on Jan 30 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos