6 ms·
I wrote a long reply, but ended up erasing it and I'll just say that many of these vulnerabilities are due to the programmer using one type (i.e. string) to rep
by aban 10y ago
I wrote a long reply, but ended up erasing it and I'll just say that many of these vulnerabilities are due to the programmer using one type (i.e. string) to represent all kinds of data that might be malicious and unsanitized, and then losing track of whether a piece of data is safe for use (e.g. to be sent to DB) or not.
I recommend checking out the Yesod web framework [0], which leverages Haskell's strong type system to provide type-safety and a whole range of nice guarantees, including preventing vulnerabilities like the ones you mentioned.
Spock [1] is another cool web framework also written in Haskell that looks quite promising.
[0]: http://www.yesodweb.com/page/about http://www.yesodweb.com/page/about
[1]: https://www.spock.li https://www.spock.li
- iopq 10y agoYesod doesn't prevent all of them. You can use "javascript:" to still do XSS, last time I checked. This is because that kind of content is valid in HTML... but maybe not what you wanted to happen
- petilon 10y agoContent Security Policy headers can be used to prevent XSS attacks. Caveats are, user must be using a modern browser, and you have to move all inline scripts out to a .js file. Read more here: http://content-security-policy.com/ http://content-security-policy.com/
- paulddraper 10y agoI don't see why javascript: is fundamentally different than other XSS vectors
- iopq 10y agobecause for other types of injections Yesod WILL actually properly encode <script> tags and make them <script> which will prevent SOME XSS exploits but it doesn't prevent all of them
- aban 10y agoThis is not true, at least not anymore. Yesod uses xss-sanitize [0], and their sanitize function does indeed prevent "javascript:" attempts. They even have a test case for it [1]. Playing around with it in the REPL: Prelude Text.HTML.SanitizeXSS Data.Text> sanitize $ pack "<IMG SRC=javascript:alert('XSS')>" "<img>" Prelude Text.HTML.SanitizeXSS Data.Text> sanitize $ pack "<IMG SRC=\"javascript:alert('XSS')\">" "<img>" Prelude Text.HTML.SanitizeXSS Data.Text> sanitize $ pack "<IMG SRC=fine>" "<img src=\"fine\">" Prelude Text.HTML.SanitizeXSS Data.Text> sanitize $ pack "<IMG SRC=\"this is ok too\">" "<img src=\"this is ok too\">" [0]: https://hackage.haskell.org/package/xss-sanitize https://hackage.haskell.org/package/xss-sanitize [1]: https://github.com/yesodweb/haskell-xss-sanitize/blob/9a9101f658b95bb8fca020a6f1ca4fad0b1364c6/test/main.hs#L39 https://github.com/yesodweb/haskell-xss-sanitize/blob/9a9101...