4 ms·
It doesnt matter where the data is coming from, it matters what it is able to do. As always with security, if the server attempts to protect the client app by e
by dobin 5y ago
It doesnt matter where the data is coming from, it matters what it is able to do. As always with security, if the server attempts to protect the client app by emulating its behaviour, it will go wrong (as the server is never able to emulate the client perfectly). This is a problem in most of the magic black security boxes (WAF, IPS, DLP etc.).
The browser knows if a certain piece of data will perform execution or not, as it is the software implementing the functionality. It is the correct app to ask, as it is the one being exploited.