Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Do you whitelist or blacklist utf-8?
- Date: Thu, 24 Feb 2011 14:58:39 +0900
- From: "Stephen J. Turnbull" <stephen@example.com>
- Subject: Re: [tlug] Do you whitelist or blacklist utf-8?
- References: <4D639689.1010302@example.com> <4D63EFBC.1020900@example.com> <AANLkTik6yyhJ-gz+NJP2yU+08ipYLaZtwZ39pn9F_b97@example.com> <8762sanqad.fsf@example.com> <AANLkTi=Ak=7E35-2xx3d4LwgG5uP8ApqeYGhP+=YPtt=@example.com>
Edmund Edgar writes: > For example, if you're letting people input a URL which you then > display as a link, they can create all kinds of mischief by putting > interesting stuff in the URL, which is going to end up between the > tags in your anchor tag. Sure, but if you're letting them input URLs that you display as links, you're already in trouble because there's one "script engine" you're never going to be able to "purify": the user at the browser. Ie, the URL can take the user to a site where "social engineering" is practiced. For example, any URL can be served by a script that simply displays the referrer page again, with all the links replaced with hacked links. Or if the script can't get the referrer page because it's not authenticated with the referring system, it can display a "Experiencing technical difficulties" page, with a hacked "Try Again" button. No, I don't *do* stuff like this, I just have that kind of mind.
- References:
- [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Shmuel Fomberg
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Josh Glover
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Stephen J. Turnbull
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Edmund Edgar
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Do you whitelist or blacklist utf-8?
- Next by Date: Re: [tlug] cacert question
- Previous by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Next by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links