Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Do you whitelist or blacklist utf-8?
- Date: Thu, 24 Feb 2011 14:50:52 +0900
- From: "Stephen J. Turnbull" <stephen@example.com>
- Subject: Re: [tlug] Do you whitelist or blacklist utf-8?
- References: <4D639689.1010302@example.com> <4D63EFBC.1020900@example.com> <AANLkTik6yyhJ-gz+NJP2yU+08ipYLaZtwZ39pn9F_b97@example.com> <8762sanqad.fsf@example.com> <AANLkTinLmawDN-reXgw=wTT5RcxeJU1qegYiLAGBYjNb@example.com>
Richard Frankum writes: > On Thu, Feb 24, 2011 at 11:02 AM, Stephen J. Turnbull > <stephen@example.com> wrote: > > Josh Glover writes: > > > What you mean is to blacklist possibly syntactic characters and only > > take characters off if you really need them. In particular, blacklist > > everything in ASCII except for the alphanumeric characters and maybe > > the space. But non-ASCII characters don't matter most of the time. > > Isn't there a vulnerability involving automatic full-width to > half-width conversion? Er, automatic conversions *after* the filter are right out. If you don't have full control of every bit in the output, you are probably vulnerable to XSS. Or do you mean that browsers convert? If browsers are doing that kind of thing, I guess you have to be paranoid, but that's a losing game. You can't hope to keep up with browser breakage. > Or would I be paranoid to think that zenkaku > punctuation should be blacklisted as well? Well, there's potential vulnerability any time you allow any input. That's why there are no commercial systems better than Orange Book level 3.
- References:
- [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Shmuel Fomberg
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Josh Glover
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Stephen J. Turnbull
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Richard Frankum
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] cacert question
- Next by Date: Re: [tlug] Do you whitelist or blacklist utf-8?
- Previous by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Next by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links