21.03.2013 Views

Problem - Kevin Tafuro

Problem - Kevin Tafuro

Problem - Kevin Tafuro

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

cases, and it is the only solution that will guarantee that cross-site scripting will be<br />

prevented. Other common attempts at a solution, such as checking the referrer<br />

header for all requests (the referrer header is easily forged), do not work.<br />

To disallow HTML in user input, you can do one of the following:<br />

• Refuse to accept anything that looks as if it may be HTML<br />

• Escape the special characters that enable a browser to interpret data as HTML<br />

Attempting to recognize HTMLand refuse it can be error-prone, unless you only<br />

look for the use of the greater-than (>) and less-than (

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!