Re: [whatwg] idea about html code security anti xss

2010-08-09 Thread Ian Hickson
On Wed, 16 Jun 2010, gabme...@westweb.at wrote: > > I had just this idea after reading so much about xss and code injection. > > I think there is a simple solution: > > 1.) > I now invent an attribute called strlen="" > > I append this to a htmlcode with strlen of 94843 bytes > including white

Re: [whatwg] idea about html code security anti xss

2010-06-16 Thread Ashley Sheridan
On Wed, 2010-06-16 at 13:33 +0200, gabme...@westweb.at wrote: > On 6/15/10 6:19 PM, gabme...@westweb.at wrote: > Hello, > > I had just this idea after reading so much about xss and code injection. > > I think there is a simple solution: > > 1.) > I now invent an attribute called strlen=""

Re: [whatwg] idea about html code security anti xss

2010-06-16 Thread gabme...@westweb.at
On 6/15/10 6:19 PM, gabme...@westweb.at wrote: Hello, I had just this idea after reading so much about xss and code injection. I think there is a simple solution: 1.) I now invent an attribute called strlen="" I append this to ahtmlcode with strlen of 94843 bytes including whitespace Th

Re: [whatwg] idea about html code security anti xss

2010-06-16 Thread Anne van Kesteren
On Wed, 16 Jun 2010 03:19:59 +0200, gabme...@westweb.at wrote: Please let me know what you think about this idea. We considered something like this before, but it was thought to be too complicated and not backwards compatible enough. In the current draft you will find which does what you

Re: [whatwg] idea about html code security anti xss

2010-06-15 Thread Arun Ranganathan
On 6/15/10 6:19 PM, gabme...@westweb.at wrote: Hello, I had just this idea after reading so much about xss and code injection. I think there is a simple solution: 1.) I now invent an attribute called strlen="" I append this to ahtmlcode with strlen of 94843 bytes including whitespace The br

Re: [whatwg] idea about html code security anti xss

2010-06-15 Thread Ashley Sheridan
On Wed, 2010-06-16 at 03:19 +0200, gabme...@westweb.at wrote: > Hello, > > I had just this idea after reading so much about xss and code injection. > > I think there is a simple solution: > > 1.) > I now invent an attribute called strlen="" > > I append this to a htmlcode with strlen of 94843

[whatwg] idea about html code security anti xss

2010-06-15 Thread gabme...@westweb.at
Hello, I had just this idea after reading so much about xss and code injection. I think there is a simple solution: 1.) I now invent an attribute called strlen="" I append this to a htmlcode with strlen of 94843 bytes including whitespace The browser know knows the exact position where the di