News on XSS
A new edition of the OWASP Newsletter was published this week.
The December 2011 edition includes an excellent article by Gareth Heyes on protecting against cross-site scripting (XSS). He recommends a process of validating the type, whitelist checking, length validation, character restriction and context dependent output escaping, illustrating this with a number of detailed examples.
One to circulate to the development team.
Posted on: 09 December 2011 at 08:30 hrs

Comments are filtered automatically and should appear shortly after they been checked.