WebApp Sec mailing list archives

RE: How to handle "special characters"


From: sparkes <sparkes () westmids biz>
Date: Thu, 11 Dec 2003 17:43:56 +0000

On Wed, 2003-12-10 at 16:55, Tony Langley wrote:
<snip>
1) Which chars are always safe (if there are any).
there aren't
2) Which chars are always dangerous.
those entered by the user
3) Those which are sometimes one or the other.
everything else

sorry to be pessamistic but this is the only truth you need to know to
stay safe

sparkes


Current thread: