2 ms·
Definitely use a battle-tested HTML sanitization library if possible. There's a million different pitfalls and footguns with XSS. See: Some of the insane XSS po
by caffeinewriter 6y ago
Definitely use a battle-tested HTML sanitization library if possible. There's a million different pitfalls and footguns with XSS. See: Some of the insane XSS polyglots out there that can be used for testing.
https://github.com/0xsobky/HackVault/wiki/Unleashing-an-Ultimate-XSS-Polyglot https://github.com/0xsobky/HackVault/wiki/Unleashing-an-Ulti...
- DarrenDev 6y agoThanks for the advice. It's number 1 on my list now.
- sammorrowdrums 6y agoAlso the stricter the content security policy the more xss holes you can plug.