3 ms·
Maybe the words 'output normalisation' are the point of confusion. I am using them as in this thread http://www.reddit.com/r/programming/comments/86kgp/xss_cro
by by 17y ago
Maybe the words 'output normalisation' are the point of confusion. I am using them as in this thread
http://www.reddit.com/r/programming/comments/86kgp/xss_cross_site_scripting_prevention_cheat_sheet/c08e4tm http://www.reddit.com/r/programming/comments/86kgp/xss_cross...
which is the context of my quote of larholm above and is a discussion about this page
http://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet http://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Pr...
Perhaps this is not common usage, but within this context I believe I am correct in saying output normalization is what prevents SQL injection.
larholm goes on to say:
"The lack of output normalization IS the security vulnerability."
"You can either normalize your output for each specific location as you encounter it, or normalize your input once in advance for all current and future output locations."
"The former beats the latter, as it is impossible for you to know how the data will be output in the future."
which also seems correct.
What is "tablespace injection"? I just googled it and there are no references to it anywhere.
http://www.google.com/search?q=%22tablespace+injection%22&hl=en&filter=0 http://www.google.com/search?q=%22tablespace+injection%22...