slides/xss-csrf/xss_defense.xml
XSS Defense
11/24
XSS Diagram (2/2)
Safer Message Board
  • • Filter ALL foreign data
  • • Let PHP help - htmlentities(), strip_tags(), utf8_decode(), etc.
  • • Only allow safe content - don't try to guess the bad
  • • Use a strict naming convention - help identify what data has been filtered
  • • The bad guys are very creative - you must be, too!