Skip to content
This repository has been archived by the owner on Jun 20, 2023. It is now read-only.

Latest commit

 

History

History
43 lines (24 loc) · 820 Bytes

0x06-OutputEncoding.md

File metadata and controls

43 lines (24 loc) · 820 Bytes

Output encoding

Allocated to Viral

Background

Principles (if any)

Positive controls

Control

How to build a secure using Control to help you, including (or even just) UML diagrams. I prefer swim lanes, but as long as it prints in landscape mode, I'm cool. I don't want portrait diagrams as this is impossible to reflow automatically using our tools.

Control

How to build a secure using Control to help you

Unit or Integration Test Cases

Abuse Cases

Negative patterns

Control that should never ever appear under pain of infinite nyan cat

e.g. shared knowledge questions or answers, or dynamic SQL queries

References


When and where to encode

SQL

HTML value

HTML attribute

XML value

XML attribute

CSS entity

CSS style