5 ms·
> how to escape characters, particularly control characters such as quotation marks, new lines and delimiters I didn't know CSV injection was a thing until it
by latch 5y ago
> how to escape characters, particularly control characters such as quotation marks, new lines and delimiters
I didn't know CSV injection was a thing until it got flagged in a pen test. Then you look around and realize it's a widespread problem and most serializers don't even have an option to escape them.
- laumars 5y agoThat’s because technically you can’t escape them: * CSV only supports one data type: string. Thus formulas are just strings processed as code by some applications based on the content of that string * CSV doesn’t support character escaping. Everything is supposed to be read unescaped. Even new lines are literal new lines. There no support for C-style escaping. If you need to have control characters then you wrap your string in quotation marks (and the fact that quotation marks are option leads to another class of bugs). If you need quotation marks inside your quotation marks then you double up the punctuation marks (ie to print “ inside “” then your string would look like “Bob said “”hello””” (Please excuse my iPhone replacing ASCII double quotes with their prettier non-ASCII counterparts)
- latch 5y agoWhile this might be technically true, I think it's worth pointing out the typical solution: append a character (usually either \t or ') to anything that looks like a formula (i.e. anything that begins with @, +, - or =). The character will be rendered/visible, but that's better than letter excel execute some arbitrary code.