What is the difference between AntiXss.HtmlEncode and HttpUtility.HtmlEncode?

后端 未结 5 2042
庸人自扰
庸人自扰 2020-12-01 01:56

I just ran across a question with an answer suggesting the AntiXss library to avoid cross site scripting. Sounded interesting, reading the msdn blog, it appears to just prov

5条回答
  •  被撕碎了的回忆
    2020-12-01 02:25

    Most XSS vulnerabilities (any type of vulnerability, actually) are based purely on the fact that existing security did not "expect" certain things to happen. Whitelist-only approaches are more apt to handle these scenarios by default.

提交回复
热议问题