On Wed, 11 Aug 2004 14:45:05 +0100, James Adams [EMAIL PROTECTED] wrote:
Hello all,
I'm in the process of trying to secure my struts application against Cross site
scripting, SQL injection style attacks.
One of the things I'm doing to prevent this is trying to restrict special characters
-Original Message-
From: James Adams [mailto:[EMAIL PROTECTED]
Sent: Wednesday, August 11, 2004 6:45 AM
To: Struts Users Mailing List
Subject: Struts security/validation
Hello all,
I'm in the process of trying to secure my struts application
against Cross site scripting,
On Wed, 11 Aug 2004 14:45:05 +0100, James Adams [EMAIL PROTECTED] wrote:
Hello all,
I'm in the process of trying to secure my struts application against Cross site
scripting, SQL injection style attacks.
One of the things I'm doing to prevent this is trying to restrict special characters
-Original Message-
From: Craig McClanahan [mailto:[EMAIL PROTECTED]
Sent: Wednesday, August 11, 2004 10:21 AM
To: Struts Users Mailing List
Subject: Re: Struts security/validation
On Wed, 11 Aug 2004 14:45:05 +0100, James Adams
[EMAIL PROTECTED] wrote:
Hello all,
I'm
McClanahan [mailto:[EMAIL PROTECTED]
Sent: Wednesday, August 11, 2004 10:21 AM
To: Struts Users Mailing List
Subject: Re: Struts security/validation
On Wed, 11 Aug 2004 14:45:05 +0100, James Adams [EMAIL PROTECTED] wrote:
Hello all,
I'm in the process of trying to secure my struts application
-Original Message-
From: Wiebe de Jong [mailto:[EMAIL PROTECTED]
Sent: Wednesday, August 11, 2004 10:32 AM
To: 'Struts Users Mailing List'
Subject: RE: Struts security/validation
I had a similar problem, which I discovered when one of my
users tried to
enter a street address
On Wed, 11 Aug 2004 10:32:04 -0700, Wiebe de Jong [EMAIL PROTECTED] wrote:
I had a similar problem, which I discovered when one of my users tried to
enter a street address containing an apostrophe. Since I use apostrophes to
delineate my text strings in my SQL statements, this caused a database
it to be l like he''s idea.
Hope this helps.
-Original Message-
From: Wiebe de Jong [mailto:[EMAIL PROTECTED]
Sent: Wednesday, August 11, 2004 1:32 PM
To: 'Struts Users Mailing List'
Subject: RE: Struts security/validation
I had a similar problem, which I discovered when one of my users
as well.
As for the XML/SOAP calls, using the serializer to create the character
entities would be good.
Thanks
Wiebe de Jong
-Original Message-
From: Craig McClanahan [mailto:[EMAIL PROTECTED]
Sent: Wednesday, August 11, 2004 10:50 AM
To: Struts Users Mailing List
Subject: Re: Struts
] wrote:
-Original Message-
From: Wiebe de Jong [mailto:[EMAIL PROTECTED]
Sent: Wednesday, August 11, 2004 10:32 AM
To: 'Struts Users Mailing List'
Subject: RE: Struts security/validation
I had a similar problem, which I discovered when one of my
users tried to
enter
Craig McClanahan wrote:
On Wed, 11 Aug 2004 10:32:04 -0700, Wiebe de Jong [EMAIL PROTECTED] wrote:
I had a similar problem, which I discovered when one of my users tried to
enter a street address containing an apostrophe. Since I use apostrophes to
delineate my text strings in my SQL
11 matches
Mail list logo