Optimized Derivative of Complex Security.

Ha.ckers.org View Over Double Trap XSS Injection



"One of the most common things I hear people say when they are writing perl programs is to remember to use the taint flag. I’ve always been one of those guys who knows enough not to leave strings un-cleansed and I never really saw the value in it. Firstly, it doesn’t tell you if something is vulnerable or not, it simply tells you that you are using it before making sure it’s clean. That in of itself may be of some use to some people, but I think it gives you a false sense of hope in a lot of ways."

The Link:
http://ha.ckers.org/blog/20070316/forgetting-global-replace-xss-woes/


The issue have been undertaken and explained under "Forgettting Global Replace XSS Woes"

[Zknk]

Posted on 3/16/2007 10:17:00 AM by 0kn0ck | 0 Comments