Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







WebApp Sec: Re: whitelisting HTML tags

Re: whitelisting HTML tags

From: Richard Moore <rich_at_westpoint.ltd.uk>
Date: Wed, 02 Nov 2005 15:30:39 +0000

Thomas Chiverton wrote:
> On Wednesday 02 November 2005 15:17, you said:
>
>>Can you simply limit your input to character markup tags like
>><b>, <i> etc?
>
>
> No.
> IE allows
> <b style="expression(alert(cookies.password))">
> type attacks, iirc.

Sure, but you don't need to support any attributes at all if
the character markup tags themselves provide sufficient flexibility.

Rich.

-- 
Richard Moore, Principal Software Engineer,
Westpoint Ltd,
Albion Wharf, 19 Albion Street, Manchester, M1 5LN, England
Tel: +44 161 237 1028
Fax: +44 161 237 1031
Received on Nov 02 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]