Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Web Development
  3. ASP.NET
  4. Proper Procedures to Prevent Cross Site Scripting.

Proper Procedures to Prevent Cross Site Scripting.

Scheduled Pinned Locked Moved ASP.NET
questioncsshelp
3 Posts 3 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B Offline
    B Offline
    badprog
    wrote on last edited by
    #1

    Issue: I need to prevent cross site scripting Current Solution: 1. Create a token based on session id and time in the Global Session Start method. 2. Store token in hidden form variable on every page load. 3. On submission, compare form variable with session token. Question: What is the proper way to implement my solution? This has to be wrong. I can not see in anyway how this would prevent CSS. Under no circumstances would the form variable differ from the session variable.

    :)

    N T 2 Replies Last reply
    0
    • B badprog

      Issue: I need to prevent cross site scripting Current Solution: 1. Create a token based on session id and time in the Global Session Start method. 2. Store token in hidden form variable on every page load. 3. On submission, compare form variable with session token. Question: What is the proper way to implement my solution? This has to be wrong. I can not see in anyway how this would prevent CSS. Under no circumstances would the form variable differ from the session variable.

      :)

      N Offline
      N Offline
      Not Active
      wrote on last edited by
      #2

      or just read this; How To: Prevent Cross-Site Scripting in ASP.NET[^]


      I know the language. I've read a book. - _Madmatt

      1 Reply Last reply
      0
      • B badprog

        Issue: I need to prevent cross site scripting Current Solution: 1. Create a token based on session id and time in the Global Session Start method. 2. Store token in hidden form variable on every page load. 3. On submission, compare form variable with session token. Question: What is the proper way to implement my solution? This has to be wrong. I can not see in anyway how this would prevent CSS. Under no circumstances would the form variable differ from the session variable.

        :)

        T Offline
        T Offline
        TweakBird
        wrote on last edited by
        #3

        Have a look on this also cross-site-scripting-in-asp-net.aspx[^]

        1 Reply Last reply
        0
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups