Skip to content

Magenaut

  • Home
  • Topics
    • Notes
    • Tutorial
    • Bug fixing
    • Extension
    • Server
  • Q&A
  • Privacy Policy
  • About

xss

How do you avoid XSS vulnerabilities in ASP.Net (MVC)?

September 2, 2022 by Magenaut

I recently noticed that I had a big hole in my application because I had done something like:

Categories ASP.NET, Q&A Tags asp.net, asp.net-mvc, xss Leave a comment

What is the difference between AntiXss.HtmlEncode and HttpUtility.HtmlEncode?

September 2, 2022 by Magenaut

I just ran across a question with an answer suggesting the AntiXss library to avoid cross site scripting. Sounded interesting, reading the msdn blog, it appears to just provide an HtmlEncode() method. But I already use HttpUtility.HtmlEncode().

Categories ASP.NET, Q&A Tags antixsslibrary, asp.net, html-encode, xss Leave a comment

How to prevent XSS (Cross Site Scripting) whilst allowing HTML input

August 31, 2022 by Magenaut

I have a website that allows to enter HTML through a TinyMCE rich editor control. It’s purpose is to allow users to format text using HTML.

Categories ASP.NET, Q&A Tags asp.net, c#, html, javascript, xss Leave a comment

Why use Microsoft AntiXSS library?

August 31, 2022 by Magenaut

When you can simply encode the data using HttpUtility.HtmlEncode, why should we use AntiXss.HtmlEncode?

Categories ASP.NET, Q&A Tags .net, antixsslibrary, asp.net, xss Leave a comment

How to sanitize input from MCE in ASP.NET?

August 30, 2022 by Magenaut

Is there a utility/function in C# to sanitize the source code of tinyMCE rich text. I would like to remove dangerous tags but like to whitelist safe html tags.

Categories ASP.NET, Q&A Tags asp.net, c#, tinymce, xss Leave a comment

How exactly do you configure httpOnlyCookies in ASP.NET?

August 29, 2022 by Magenaut

Inspired by this CodingHorror article, “Protecting Your Cookies: HttpOnly“

Categories ASP.NET, Q&A Tags asp.net, cookies, httponly, xss Leave a comment

What characters or character combinations are invalid when ValidateRequest is set to true?

August 29, 2022 by Magenaut

I’ve tried looking at the Microsoft site and Googling this but nobody seems to have an answer aside from the < and the >. There’s more to it than that though. I’ve noticed that the HTML entity starter of &# is invalid. Is there anything else? Does anyone have a complete list?

Categories ASP.NET, Q&A Tags .net, asp.net, security, sql-injection, xss Leave a comment

Is PagesSection.ValidateRequest enough to prevent XSS in asp.Net

August 27, 2022 by Magenaut

In asp.net is the PagesSection.ValidateRequest method enough to prevent all XSS attacks or is there something more that needs to be done?

Categories ASP.NET, Q&A Tags .net, asp.net, validation, xss Leave a comment

Sanitize HTML before storing in the DB or before rendering? (AntiXSS library in ASP.NET)

August 27, 2022 by Magenaut

I have an editor that lets users add HTML that is stored in the database and rendered on a web page. Since this is untrusted input, I plan to use Microsoft.Security.Application.AntiXsSS.GetSafeHtmlFragment to sanitize the HTML.

Categories ASP.NET, Q&A Tags antixsslibrary, asp.net, html-sanitizing, xss Leave a comment
  1. michealSmith07 on Is there a way to dynamically refresh the less command?August 21, 2022

    That is a very nice post. I like this post.

  2. anonymous on Fix libwacom9 dependency issue when upgrade DebianJune 27, 2022

    saved my day!! Thanks for the help…

  3. sreedhar on Fix libwacom9 dependency issue when upgrade DebianMay 10, 2022

    Thanks its working

  4. saintnick on Fix libwacom9 dependency issue when upgrade DebianMay 10, 2022

    remove libwacom2 worked for me as well

  5. ranafoul on Fix libwacom9 dependency issue when upgrade DebianApril 22, 2022

    apt remove libwacom2 helped on kali 2022.01. gr8

.net ajax asp.net asp.net-core asp.net-mvc asp.net-mvc-3 asp.net-mvc-4 asp.net-web-api bash c# command-line css custom-post-types custom-taxonomy dataframe dictionary django entity-framework functions gridview html iis javascript jquery json linux list matplotlib numpy pandas php plugin-development plugins posts python python-2.7 python-3.x security shell shell-script sql string vb.net webforms wp-query

© 2026 Magenaut • Built with GeneratePress