Re: xss filter

2011-01-19 Thread Tom McNeer
On Tue, Jan 18, 2011 at 8:37 PM, Nick Gleason wrote: > > Thoughts? > You might want to contact the developer of Portcullis, John Mason, directly. His e-mail is mason |at| fusionlink.com. -- Thanks, Tom Tom McNeer MediumCool http://www.mediumcool.com 1735 Johnson Road NE Atlanta, GA 30306 4

xss filter

2011-01-18 Thread Nick Gleason
Hi folks, We've implemented the portcullis xss filter with success but we are coming across some false positives that I wanted to run by the big brains on this list. One example is the word "exec" as in "marketing exec" which is getting filtered when it shouldn't