Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Do you whitelist or blacklist utf-8?
- Date: Wed, 23 Feb 2011 10:54:33 +0200
- From: Shmuel Fomberg <owner@example.com>
- Subject: Re: [tlug] Do you whitelist or blacklist utf-8?
- References: <4D639689.1010302@example.com> <4D63EFBC.1020900@example.com> <4D64C5DD.1040607@example.com>
- User-agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20101207 Thunderbird/3.1.7
Hi Dave. On 2011/02/23 10:31, Dave M G wrote:I think that every character that is above the ascii range can be safely passed.Shmuel, I'd love to do a white list on my utf-8 strings... however, it seems like it's really tough to set up a white list that doesn't refuse any non-latin characters. I saw one page that showed regular expressions for filtering by languages... but you had to set up a huge array to account for every single language.So you don't need a huge array. just small one.All that I wrote was about SQL-injection. XSS is one layer above the individual characters. but first you need to tell us something about your data. is the user allowed to enter HTML tags?What to people do when they want to ensure Japanese text is free of any XSS-capable charactersor are you using different mark-down scheme? Shmuel.
- Follow-Ups:
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- References:
- [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Shmuel Fomberg
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Solaris tar: how to pre-pend a parent directory?
- Next by Date: [tlug] Answered: Re: Solaris tar: how to pre-pend a parent directory?
- Previous by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Next by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links