Why use a whitelist for HTML sanitizing?

前端 未结 7 2147
野趣味
野趣味 2020-12-06 18:39

I\'ve often wondered -- why use a whitelist as opposed to a blacklist when sanitizing HTML input?

How many sneaky HTML tricks are there to open XSS vulnerabilities?

7条回答
  •  爱一瞬间的悲伤
    2020-12-06 18:45

    Because other tags can break the layout of a page. Imagine what would happen if someone injects