HTML :: StripScripts still safe to remove modern exploits?

I need a way in Perl to break naughty things like XSS, image interjection and work.

I found HTML :: StripScripts , but it has not been updated for two years, and I am not aware of all the new feats.

Is it safe?

What other markup languages ​​(in Perl) would you use?

+3
source share
2 answers

HTML :: StripScripts is a whitelist and can use a tree-based parser and should be as safe as a whitelist.

0
source

XSS is an extensive topic, and adventures appear every day.

/​​ .

( ) . html/ , . <b>, <i>

Defang / XSS lib perl cpan

OWASP XSS Cheat Sheet

CAL9000, , / XSS

+2

Source: https://habr.com/ru/post/1707742/


All Articles