5 ms·
Noob question. I get that this is a problem and what it could do, but wouldn't doing simple checks and validations of any client input solve this problem?
by taylorwc 10y ago
Noob question. I get that this is a problem and what it could do, but wouldn't doing simple checks and validations of any client input solve this problem?
- deleted 10y ago[deleted]
- ecares 10y agoNot a noob question ;) As stated in the presentation at the end of the article, data validation is one of the methods to prevent such attacks. Soon, there will be a new article offering a few methods to reduce risks in this area.
- dozzie 10y agoThe problems are to a) get to the point when all your input is validated and b) stay there. It's easy to validate some data, it's horribly difficult to validate it all (or rather, it's horribly easy to forget something). Exactly the same could be said about SQL injection, and its solution is prepared queries with value placeholders, which is an idea over a dozen years old. Apparently MongoDB has not caught up yet with SQL from decade ago.
- wcarron 10y agoAs another poster replied: Yes, validation is one method to reduce the methods of attacking. Client side is essentially useless in these cases, since they can just bypass the gui by sending HTTP requests (which can then contain the db methods) from the command line. What is needed is server side validation. Pretty much the same as client side, but most of the time a bit more robust. The problem is validating ALL the input. Like, creating this comment. Validation is really easy for this comment. But what about something where you upload images? PDFs are well known attack vectors. So are SVGs. How can you be sure there's nothing hiding in those? It's possible. It just becomes increasingly difficult to cover each case.
- virmundi 10y agoI find it odd that in 2016 we don't have a better way of centralizing that type of logic better. I don't know of a single framework that will generate front end logic from annotations on a class and then run the logic against the same annotations on the server. Spring gets you half way. Not the rest. -- edit grammer --