Re: Extended ASCII characters used for injection

john s <[email protected]>
Newsgroups gmane.comp.security.web-applications
Message-ID <[email protected]>
On Tue, Oct 19, 2010 at 8:06 AM, Nibbler <[email protected]> wrote:
>
> I have a web app and I want to block special characters in URL on the
> web server. Do you know if there is a risk of injection (XSS...) with
> extended ASCII char (%7f-%ff)?
> Is there any reason to block these characters?

Whether or not there is a known attack vector in the character-set, it
is a good practice to enumerate & allow only what you need
(whitelisting) rather than trying to define and block badness
(blacklisting)...



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.