2 ms·
I have also seen backend application which strip out certain "bad" tags (i.e. <script>). I remember being able to perform an XSS attack by sending a payload th
by gskourou 6y ago
I have also seen backend application which strip out certain "bad" tags (i.e. <script>).
I remember being able to perform an XSS attack by sending a payload that looked like:
<sc<script>ript>alert(/XSS/)</sc<script>ript>
This passed the WAF inspection, but then got trimmed by the backend application and this is what was left:
<script>alert(/XSS/)</script>
written in the page source.
Maybe I'll write about that case too if I find where I put the attack evidence.
You can anyway see that bad validation by the actual application programmers can disable the WAF's capabilities.
- colejohnson66 6y agoIsn’t the correct solution to replace '<' and '>' with '<' and '>'?
- krapp 6y agoYeah, escaping entities when rendering, using prepared statements in the database. It's not rocket science.
- gskourou 6y agoamen
- tannhaeuser 6y agoOr, you know, using ordinary SGML validation which has the capability to block disallowed elements since 1986.
- yyyk 6y agoThe correct solution is to apply Content-Security-Policy plus character escaping as needed.