Untitled Document
SecurView  
HomeSite Map
Untitled Document
 
XSIO - Cross Site Image Overlaying
REMEDIATION
The simplest and the most effective approach towards addressing this issue is to filter all html tags from user inputs. However, if accepting and processing html tags is necessary, it is recommended to put the following additional filters.

Restricting position and size of an image
If users need to be allowed to post images, the position for the user submitted image must be predefined in DOM tree.

Restricting user to set style attributes
Never let the user set any attributes (like "style"). This type of manipulation can be made harder by using the "container inside a container" approach with CSS.

Input and output filters
In order to defend a web application against XSIO, one just needs better filters in place. If all the input characters are not filtered, a developer can do simple html references. Developer should take extreme care while handling anything that has been inputted by a user, properly validating and sanitizing the user- inputted data.
Click here to download PDF version  
Untitled Document
Unified Communication (UC) Management
OnDEMAND Services
PCI Compliance
Untitled Document
COMPANY TECHNOLOGY OnDEMAND SERVICES MANAGED SERVICES COMPLIANCE SOLUTIONS PHYSICAL SECURITY PARTNERS/CUSTOMERS SUPPORT
© 2007 SecurView, Inc. All rights reserved. SecurView and the the SecurView logo are trademakrs of SecurView, Inc.
All other trademarks mentioned in this document or Website are the property of their respective owners.