php - filter metacharacters from user input in xss attack -
on site on admin login page if this
http://www.domain.com/admin/index.php/%22onclick=document.location="http://www.google.com">
and click somewhere page redirects. read somewhere need filter metacharacters. after hours of googling cant find out how can stop this. above see isnt doing or post. how can block this?
no, don't character filtering / massaging. need treat user input, regardless of how sent you, evil virus , handle such.
how link being generated? wrote or user put sort of cms?
i'm not sure there enough information directly should never redirect data user passes page. instead, use information pass determine should go.
Comments
Post a Comment