webappsec October 2010 archive
Main Archive Page > Month Archives  > webappsec archives
webappsec: Extended ASCII characters used for injection

Extended ASCII characters used for injection

From: Nibbler <enibbler_at_nospam>
Date: Tue Oct 19 2010 - 13:06:25 GMT
To: webappsec@securityfocus.com

Hi list,

I have a web app and I want to block special characters in URL on the
web server. Do you know if there is a risk of injection (XSS...) with
extended ASCII char (%7f-%ff)?
Is there any reason to block these characters?

Thanks
Regards,
Nib

This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now!
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------