|
|
Choosing A Webhost: |
Re: whitelisting XSS/HTML-injection defense: msg#00005apache.mod-security.user
Rude Yak wrote: I've read the portion of the doc that covers XSS, i.e. Brave attempt but I don't think it is possible to reliably whitelist HTML tags using regular expressions only. In this case I think custom programming is the way to go. This is something I want to add to a future ModSecurity release: create a hook to allow custom code to be plugged-in to verify the incoming data. -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org ------------------------------------------------------- This SF.Net email is sponsored by: Power Architecture Resource Center: Free content, downloads, discussions, and more. http://solutions.newsforge.com/ibmarch.tmpl
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: 1.9b4 SecFilterRemove question, Ivan Ristic |
|---|---|
| Next by Date: | [ANNOUNCE] ModSecurity 1.9RC1 has been released, Ivan Ristic |
| Previous by Thread: | whitelisting XSS/HTML-injection defense, Rude Yak |
| Next by Thread: | Fedora, Mod-Security, PID issues, Frank |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |