3 ms·
> Attempting to remove dangerous meta-characters from the input stream leaves a number of risks unaddressed. We encourage developers to restrict variables used
by billyhoffman 5y ago
> Attempting to remove dangerous meta-characters from the input stream leaves a number of risks unaddressed. We encourage developers to restrict variables used in the construction of pages to those characters that are explicitly allowed and to check those variables during the generation of the output page
Nice to see that allow-list input validation was proscribed as a solution to XSS (and really any injection attack) from the beginning. It even explicitly warns against trying to do deny-list.
Trying to sanitize or defang user supplied input is always very difficult and a handy bad-code-smell indicator during code review. It has a ton of corner cases and edge cases and by its very nature it fails deadly: can an attacker discover an injection using characters that aren’t in the denial list? They win. Oh you’re sanitizing function simply removes the malicious characters? Attacker constructs an injection string that contains an valid injection that is constructor by your sanitizer function removing characters.
Nice also see reference to output e coding as well. Defense in depth is always a good idea. It also protects you from injection through other means that may be are not properly validated.