danielmiessler.com | posterous

grep understanding

« Back to posts
  • Viewed
    times

Filed under

  • Web Application Security
  • XSS
May 8, 2011

There's more to HTML escaping than &, <, >, and " | Wonko

  • Edit
  • Delete
  • Tags
  • Autopost
If I had a dollar for every HTML escaper that only escapes &, <, >, and ", I'd have $0. Because my account would've been pwned via XSS."

This was exaggeration for effect—there aren’t many cases where a simple XSS injection could actually empty a bank account—but I wanted to make a point.

via wonko.com

Tweet
  • 0 responses
  • Like
  • Comment