What is the difference between AntiXss.HtmlEncode and HttpUtility.HtmlEncode?

后端 未结 5 2043
庸人自扰
庸人自扰 2020-12-01 01:56

I just ran across a question with an answer suggesting the AntiXss library to avoid cross site scripting. Sounded interesting, reading the msdn blog, it appears to just prov

5条回答
  •  情书的邮戳
    2020-12-01 02:18

    We use the white-list approach for Microsoft's Windows Live sites. I'm sure that there are any number of security attacks that we haven't thought of yet, so I'm more comfortable with the paranoid approach. I suspect there have been cases where the black-list exposed vulnerabilities that the white-list did not, but I couldn't tell you the details.

提交回复
热议问题