4 ms·
Example A field accepts a username. A good regex would be to verify that the data consists of the following [0-9a-A-Z]{3,10}. The data is rejected if it doe
by wulczer 15y ago
Example A field accepts a username. A good regex would
be to verify that the data consists of the following
[0-9a-A-Z]{3,10}. The data is rejected if it doesn't
match.
I guess then that pg won't be able to sign up for your service... Nor will donfernandovillaverde79.
- bennysaurus 15y agoIn the example given? No, the bounds are restricted. The actual text above though is the important bit: The variations of attacks are enormous. Use regular expressions to define what is good and then deny the input if anything else is received. In other words, we want to use the approach "Accept Known Good" instead of "Reject Known Bad"
- aw3c2 15y agoThis also keeps out non-latin alphabet users. Like half the world's population.
- skymt 15y agoIt's difficult to accept non-latin characters in usernames without making username spoofing trivial. For example, I could sign up for an account as `аw3c2', pretending to be you. What looks like `a' there is actually `а', a Cyrillic letter with its own Unicode code point. Assuming a website where user impersonation is an issue (say, an auction site where a homoglyph attack could be used to scam a seller into sending the goods to a different address), one would need to blacklist all likely homoglyphs and duplicate characters, or just stick to ASCII. (I'm sure users are accustomed to using ASCII usernames, though it's not ideal.)
- wisty 15y agoIt also makes it hard for users to log in using a dumber input device than usual. Then there is unicode normalization. OSX might decide to encode "e-with-an-accent" as two code points, while Windows will combine them into a single code point. Users will not be impressed if they can't log in because their OS doesn't use the right encoding and the web site forgot to normalize.
- rmc 15y agoIn this case you should use Unicode Normalisation to turn all input into one canonical form, either with or without combining diacritics
- zobzu 15y agoThe example is there for the guideline about "only filter known good" That said, it could confuse people. I'd suggest to fill a bug at bugzilla.mozilla.org to put a broader example, or to specify that you might want different characters in the known good list, specially for non-latin writing people, cause yeah, many would just copy paste it without thinking further.
- qjz 15y agoOn a related note, one of the web sites I frequently use stripped all spaces from my password without notice before storing it on the server. So when I registered with a password like 'I am Sam', I found I could only log in using 'IamSam'. Any attempt to use the original password caused an error. I reported this to the site admin, and the solution they came up with was to silently strip the spaces from the password as it is typed into the form. Now I can type in 'I am Sam', but 'IamSam' is the actual password sent to the server. File this under '2 wrongs don't make a right'.
- elehack 15y agoA while ago, Tracfone's web site had a rather disappointing bug. Both the account registration and login flows did password validation, and used different validation functions. The result was that I could create an account with a password containing special characters that the authentication system would reject as containing invalid characters (and therefore not even try to verify against my stored password/hash). Moral: account registration and authentication must use the same password normalization functions, and if you validate at auth time (which is pointless, but hey), the validation function must be the same as the registration one. Better moral: just don't do silly things with passwords. Encrypt them and store them, accepting whatever the user wants to send you that's sufficiently long/high-entropy.