Talk in English - UK at ConFoo 2012
View Slides: http://talks.bluesmoon.info/iwygwyetg/input-sanitization.pdf
Short URL: https://joind.in/talk/c4020
(QR-Code (opens in new window))
Is what you get what you expect to get?
Comments
Comments are closed.
What does the slide #2 mean (IWYGWYETG)?
Apart from it, pretty nifty tricks on XSS which every form designer should be aware about!
I recently found someone who'd done zero validations on a production site form, and it had been like that for 5 months. Thankfully enough, probably hackers were dumb enough to realise that maybe XSS exploit checks were in place, and hence they didn't do anything nasty. Phew!
IWYGWYETG is the title of the post (Is What You Get What You Expect To Get)