RE: Persistent XSS, behind the scenes tutorial. 07-29-2013, 08:07 PM
#8
Nice tutorial 
I'd just like to add:
htmlentities() converts everything that has a HTML entity equivalent, htmlspecialchars() converts only known malicious characters. This is important to know for optimizing your code, htmlentities() can prevent unknown attacks, but will be more heavy on the memory.
Also, you can use these functions as much as you want, but when you reflect a value into a script, it won't help very much. Always always always check where the reflected values are located and escape accordingly, If you reflect to a script, also escape the javascript code (instead of just the HTML).
The best practice however is to simply have a character whitelist and simply remove anything that does not match it.
In your example, you ask for the users name. Names consist only from letters, so why not simply remove everything except upper-case and lower-case letters? This will prevent any bad stuff from getting in

I'd just like to add:
htmlentities() converts everything that has a HTML entity equivalent, htmlspecialchars() converts only known malicious characters. This is important to know for optimizing your code, htmlentities() can prevent unknown attacks, but will be more heavy on the memory.
Also, you can use these functions as much as you want, but when you reflect a value into a script, it won't help very much. Always always always check where the reflected values are located and escape accordingly, If you reflect to a script, also escape the javascript code (instead of just the HTML).
The best practice however is to simply have a character whitelist and simply remove anything that does not match it.
In your example, you ask for the users name. Names consist only from letters, so why not simply remove everything except upper-case and lower-case letters? This will prevent any bad stuff from getting in
Staff will never ever ask you for your personal information.
We know everything about you anyway.
We know everything about you anyway.




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)