Security Blog

The latest news and insights from Google on security and safety on the Internet

Reducing XSS by way of Automatic Context-Aware Escaping in Template Systems

31 Μαρτίου 2009
Share on Twitter Share on Facebook
Google

9 σχόλια :

miked είπε...

I like django solution - all data substitution are dangerouse, but when you need html you place 'safe' filter, and now you start really thinking safe it or not

1 Απριλίου 2009 στις 7:49 π.μ.
jwilliams είπε...

For some additional background on context sensitive escaping in HTML, check out OWASP's XSS Prevention Cheat Sheet at http://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet. Are there differences with what is recommended there?

2 Απριλίου 2009 στις 4:32 μ.μ.
Jack O'Sullivan είπε...

You guys are a little over my head, but you guys are awesome. Thanks for all the info!
Jack O'Sullivan
Bedroom Sets

5 Απριλίου 2009 στις 11:37 μ.μ.
Olivvv είπε...

Hi

So you consider that on large applications, the approach of filtering data when it enters the program is not maintainable. Some dev will forget it, and there is no way to test if all the necessary filters are in place, so you put a big bold filter on the output.

It seems efficient at cleaning the output from xss attacks style, but
isn't the remedy worst that the disease ?

If, when it was really necessary devs were forgetting to properly filters inputs, now that there is that filter-on-output system, won't they be even more lazy ?

It seems to me that this approach hardens protection against xss-attacks, and weaken protection against more old school attacks.

olivvv

14 Απριλίου 2009 στις 6:54 π.μ.
Jad είπε...

Thanks all for the good comments and information.

@jwilliams: Thanks for the link to the OWASP document, I hadn't seen it before. The different contexts (represented by the individual rules) in that document align well with the ones we targeted, which is great. There are small differences such as handling content in Javascript outside of string literals, CSS in style tags and perhaps more handling of non-quoted attributes but these are all reconcilable. Note that I didn't review the escaping functions themselves.

@olivvv: We didn't write about input validation here as the blog post was already lengthy. We certainly encourage consistent and strong input validation because it helps to prevent not only XSS bugs but also many other correctness and security problems too. There is no reason you can't have both at the same time (input validation and output escaping). That said, in many cases, input validation alone is not a sufficient defense against XSS.

14 Απριλίου 2009 στις 6:34 μ.μ.
yo είπε...

Please roll these changes into the version of clearsilver that is available on appengine:

http://code.google.com/p/googleappengine/issues/detail?id=1363

19 Απριλίου 2009 στις 2:58 μ.μ.
Daira Hopwood είπε...

It seems that the inferred filter may be less specific than the actual syntax for the value to be substituted. For instance, the CSS example expects a colour, but the inferred filter will only reject specific unsafe CSS constructs, by the sound of it.

Other than reading the source code, is there any documentation on precisely what each escaping filter does?

20 Απριλίου 2009 στις 9:19 μ.μ.
Swedish Research είπε...

Its here the quality work clean of little else is done at Google. Very good blog post.

Escape-sequences cause so much problem and have do it so long. People patching code from different generations, different projekt and so on.

Very usefull.

21 Απριλίου 2009 στις 9:29 μ.μ.
koolo είπε...

IF you want to help remove malware then go here..

http://remove-malware.com/

10 Μαΐου 2009 στις 2:53 π.μ.

Δημοσίευση σχολίου

  

Ετικέτες


  • #sharethemicincyber
  • #supplychain #security #opensource
  • AI Security
  • android
  • android security
  • android tr
  • app security
  • big data
  • biometrics
  • blackhat
  • C++
  • chrome
  • chrome enterprise
  • chrome security
  • connected devices
  • CTF
  • diversity
  • encryption
  • federated learning
  • fuzzing
  • Gboard
  • google play
  • google play protect
  • hacking
  • interoperability
  • iot security
  • kubernetes
  • linux kernel
  • memory safety
  • Open Source
  • pha family highlights
  • pixel
  • privacy
  • private compute core
  • Rowhammer
  • rust
  • Security
  • security rewards program
  • sigstore
  • spyware
  • supply chain
  • targeted spyware
  • tensor
  • Titan M2
  • VDP
  • vulnerabilities
  • workshop


Archive


  •     2026
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2025
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2024
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2023
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2022
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2021
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2020
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2019
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2018
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2017
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2016
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2015
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2014
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2013
    • Δεκ
    • Νοε
    • Οκτ
    • Αυγ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2012
    • Δεκ
    • Σεπ
    • Αυγ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
    • Ιαν
  •     2011
    • Δεκ
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαΐ
    • Απρ
    • Μαρ
    • Φεβ
  •     2010
    • Νοε
    • Οκτ
    • Σεπ
    • Αυγ
    • Ιουλ
    • Μαΐ
    • Απρ
    • Μαρ
  •     2009
    • Νοε
    • Οκτ
    • Αυγ
    • Ιουλ
    • Ιουν
    • Μαρ
  •     2008
    • Δεκ
    • Νοε
    • Οκτ
    • Αυγ
    • Ιουλ
    • Μαΐ
    • Φεβ
  •     2007
    • Νοε
    • Οκτ
    • Σεπ
    • Ιουλ
    • Ιουν
    • Μαΐ

Feed

Follow
Give us feedback in our Product Forums.
  • Google
  • Privacy
  • Terms