Is there any way to put malicious code into a regular expression?

前端 未结 6 693
没有蜡笔的小新
没有蜡笔的小新 2020-12-02 04:24

I want to add regular expression search capability to my public web page. Other than HTML encoding the output, do I need to do anything to guard against malicious user input

6条回答
  •  刺人心
    刺人心 (楼主)
    2020-12-02 04:44

    You'll want to read this paper:

    Insecure Context Switching: Inoculating regular expressions for survivability The paper is more about what can go wrong with regular expression engines (e.g. PCRE), but it may help you understand what you're up against.

提交回复
热议问题