18 ms·
Thanks. I'll look into that. I thought I was stripping out all scripts, but I wasn't checking the image and link insertion. Much appreciated.
by DarrenDev 6y ago
Thanks. I'll look into that. I thought I was stripping out all scripts, but I wasn't checking the image and link insertion. Much appreciated.
- caffeinewriter 6y agoDefinitely use a battle-tested HTML sanitization library if possible. There's a million different pitfalls and footguns with XSS. See: Some of the insane XSS polyglots out there that can be used for testing. https://github.com/0xsobky/HackVault/wiki/Unleashing-an-Ultimate-XSS-Polyglot https://github.com/0xsobky/HackVault/wiki/Unleashing-an-Ulti...
- DarrenDev 6y agoThanks for the advice. It's number 1 on my list now.
- sammorrowdrums 6y agoAlso the stricter the content security policy the more xss holes you can plug.