<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Preventing JavaScript Injection Attacks</title><link>http://www.asp.net</link><pubDate>Tue, 20 Apr 2010 03:53:35 GMT</pubDate><generator>umbraco</generator><description>Comments for Preventing JavaScript Injection Attacks</description><language>en</language><atom:link href="http://www.asp.net/rss/comments/27481" rel="self" type="application/rss+xml" /><item><title>Comment Posted by cv_vikram</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Tue, 26 Aug 2008 20:42:07 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006982</guid><description><![CDATA[ <p>Thanks for the video....</p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/cv_vikram.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by amanprogrammer</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Tue, 16 Sep 2008 16:29:55 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006983</guid><description><![CDATA[ <p>You rock Stephen .</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/amanprogrammer.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by developer_rk1</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Mon, 29 Sep 2008 04:52:16 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006984</guid><description><![CDATA[ <p>Excellent Work Stephen!</p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/developer_rk1.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by bikedude</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Thu, 09 Oct 2008 13:06:25 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006985</guid><description><![CDATA[ <p>Does the MVC framework do something to disable ASP.Net&#39;s built-in protection for JavaScript injection attacks?</p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/bikedude.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by jclark434175</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Sun, 19 Oct 2008 22:11:13 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006986</guid><description><![CDATA[ <p>Great video stephen. You really know how to teach MVC.</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/jclark434175.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by jmoviedo</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Sun, 16 Nov 2008 19:31:56 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006987</guid><description><![CDATA[ <p>That is helpful. Thanks</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/jmoviedo.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by lgbaustin</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Tue, 09 Dec 2008 19:31:40 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006988</guid><description><![CDATA[ <p>Very good .. you just convinced me to get your book.</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/lgbaustin.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by legerj4463</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Thu, 18 Dec 2008 13:40:03 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006989</guid><description><![CDATA[ <p>Nice video. Just wondering however, wouldn&#39;t it make sense to actually not save a message whose content contains a script tag? Creating a helper method that ensures that the string to be saved perhaps before encoding, precludes any &lt;script&gt; content... </p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/legerj4463.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by pinfeather4200</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Tue, 23 Dec 2008 14:14:39 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006991</guid><description><![CDATA[ <p>Im watching these and getting alot; however, Im searching for a reason why I would develop in this fashion as it seems much more complex. &#160;Is it faster? &#160;Anyway will keep going to see if that reveals itself. &#160;Good style and video!!!</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/pinfeather4200.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by .netDeveloper22</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Sat, 24 Jan 2009 03:24:17 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006992</guid><description><![CDATA[ <p>Great video..</p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/.netDeveloper22.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by Djibril_Chimere_DIAW</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Mon, 16 Mar 2009 09:42:20 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006995</guid><description><![CDATA[ <p>Thanks! J&#235;r&#235;j&#235;f!</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/Djibril_Chimere_DIAW.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by vinothkumarsi</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Tue, 21 Apr 2009 11:49:37 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006996</guid><description><![CDATA[ <p>Nice Video</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/vinothkumarsi.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by shehandavy</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Mon, 04 May 2009 07:43:03 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006997</guid><description><![CDATA[ <p>Thanks Stephen! Great tip!</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/shehandavy.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by haithemara</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Mon, 11 May 2009 02:18:39 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006998</guid><description><![CDATA[ <p>great video Stephen . How about a video that prevent sqlinjection .</p><p>Thank you.</p>]]></description><enclosure length="0" type="image/png" url="http://i1.asp.net/avatar/haithemara.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by NYCharles</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Fri, 15 May 2009 20:11:34 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000006999</guid><description><![CDATA[ <p>I actually like the second approach (encode text when adding it to database) better for simplicity and security reason. Simplicity - You don&#39;t have to encode the text on every page that display the text. Security - If you forget to encode it, you get the JavaScript execution. </p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/NYCharles.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by jharr</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Fri, 29 May 2009 05:01:29 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007000</guid><description><![CDATA[ <p>Very useful video! Can&#39;t wait for more!</p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/jharr.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by hareshambaliya</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Tue, 14 Jul 2009 05:30:43 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007001</guid><description><![CDATA[ <p>very userful video related security of web site while developing in MVC</p>]]></description><enclosure length="0" type="image/png" url="http://i2.asp.net/avatar/hareshambaliya.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by v.vivek</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Fri, 31 Jul 2009 09:10:01 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007002</guid><description><![CDATA[ <p>very Useful video,Thanks Stephen.</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/v.vivek.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by kannank7</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Sun, 20 Sep 2009 08:07:52 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007003</guid><description><![CDATA[ <p>very very informative.. thanks </p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/kannank7.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by mohammed.ibrahim</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Thu, 24 Sep 2009 11:34:35 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007004</guid><description><![CDATA[ <p>I would also recommend using Regular Expression.</p><p></p><p>As it will give the developer more control on what the user will type.</p><p></p><p>Thanks</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/mohammed.ibrahim.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by mac10</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Tue, 06 Oct 2009 06:44:42 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007005</guid><description><![CDATA[ <p>Thanks for the video.</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/mac10.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by Westnyorai</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Sun, 17 Jan 2010 04:43:58 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007006</guid><description><![CDATA[ <p>Hi Stephen, your video is a great intro, but... with all the new html rich controls out there today, such as htmleditor that comes with ajax control toolkit there are times you will need to be a bit more advance. May I suggest the following function I wrote using the assistant of several other users&#39; scripts online. (I would name them if I could)</p><p></p><p><a rel="nofollow" href="http://sanzon.wordpress.com/2010/01/17/whitelist-html-tags-advance-methods-for-prevention-against-javascript-injections/" target="_blank">sanzon.wordpress.com/</a></p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/Westnyorai.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by gangelo</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Thu, 11 Mar 2010 18:55:35 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007007</guid><description><![CDATA[ <p>Stephen, why do we need your BIG head, bottom right, taking up valuable vid real estate in these vids!!! :)</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/gangelo.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by fcartu</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Mon, 22 Mar 2010 13:03:49 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007009</guid><description><![CDATA[ <p>Hey, great video. Actually i like to save all the text with Server.HtmlEnconde directly to the database!!!</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/fcartu.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item><item><title>Comment Posted by vvvvvdev</title><link>http://www.asp.net/mvc/videos/mvc-2/how-do-i/preventing-javascript-injection-attacks</link><pubDate>Tue, 20 Apr 2010 03:53:35 GMT</pubDate><guid isPermaLink="false">00000000-0000-0000-000000007010</guid><description><![CDATA[ <p>you are the genius stephen</p>]]></description><enclosure length="0" type="image/png" url="http://i3.asp.net/avatar/vvvvvdev.jpg?forceidenticon=false&amp;dt=635072251200000000&amp;enableAvatar=False&amp;cdn_id=2013-05-10-001" /></item></channel></rss>