Asp.NET Access Control: Using Brackets in Passwords

I am using the standard asp: Login control, and we have a user who recently changed his password by including angular brackets in it. When she tries to log in, she receives an error message, and I get the standard "dangerous request" exception.

I know I can set ValidateRequest = "false" on the page to deny this, but I was hoping someone knew about a better way.

Thank!

Decision

We forced her to change her password in order to remove the bracket. The pragmatist wins again. Thanks for answers.

+3
source share
3 answers

, , . , /, , .

, , < > .

, - Web Protection Library -.

+1

JavaScript html- .

+1

, , , . "" , , .

- . , ( , ), - , , / .

0

Source: https://habr.com/ru/post/1753964/


All Articles