RE: Extended ASCII characters used for injection
"Chris Weber" <[email protected]>
| Newsgroups | gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
You'd be blocking legitimate usage of many different character encodings including UTF-8 and ISO-8859-1 if you blocked 0x77 - 0xff. -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Nibbler Sent: Tuesday, October 19, 2010 6:06 AM To: [email protected] Subject: Extended ASCII characters used for injection Hi list, I have a web app and I want to block special characters in URL on the web server. Do you know if there is a risk of injection (XSS...) with extended ASCII char (%7f-%ff)? Is there any reason to block these characters? Thanks Regards, Nib This list is sponsored by Cenzic -------------------------------------- Let Us Hack You. Before Hackers Do! It's Finally Here - The Cenzic Website HealthCheck. FREE. Request Yours Now! http://www.cenzic.com/2009HClaunch_Securityfocus -------------------------------------- This list is sponsored by Cenzic -------------------------------------- Let Us Hack You. Before Hackers Do! It's Finally Here - The Cenzic Website HealthCheck. FREE. Request Yours Now! http://www.cenzic.com/2009HClaunch_Securityfocus --------------------------------------