by Tom T. » Sun May 06, 2012 11:48 pm
Thrawn wrote:Tom T. wrote:Thrawn, please see
ABE Rules .pdf, section 1.3. As I read it, it does in fact differentiate literals from regular expressions. See if it doesn't read that way to you also, thanks.
ABE rules can have literals, yes, but we're talking about InjectionChecker exceptions.
I get so many ABE questions vs. XSS that It seems ABE was on my mind.
(Slight face-saving: You came up with an ABE rule also, and a good one.)
I hope that's my one big mistake for the day. Now, just two little ones, and I'm good.
(Thanks for the catch. Many eyes = fewer errors.)
ETA: I'd love to hear the site's reply to an inquiry, but the most frequent answer is "Use another browser."
Since your profile here is publicly viewable, it is not a secret that you're a programmer/analyst yourself. Please tell me you'd never code a site so poorly that *navigating within the same site* (especially a secure one

) would produce XSS messages...
[rant] Lazy, sloppy, or downright incompetent site designers seem to be pandemic -- and IMHO, banks and financial institutions
are the
worst. [/rant]
[quote="Thrawn"][quote="Tom T."][b]Thrawn[/b], please see [url=http://noscript.net/abe/abe_rules.pdf]ABE Rules .pdf[/url], section 1.3. As I read it, it does in fact differentiate literals from regular expressions. See if it doesn't read that way to you also, thanks.
[/quote]ABE rules can have literals, yes, but we're talking about InjectionChecker exceptions.[/quote]
I get so many ABE questions vs. XSS that It seems ABE was on my mind. :?
(Slight face-saving: You came up with an ABE rule also, and a good one.)
I hope that's my one big mistake for the day. Now, just two little ones, and I'm good. :lol:
(Thanks for the catch. Many eyes = fewer errors.)
[b]ETA:[/b] I'd love to hear the site's reply to an inquiry, but the most frequent answer is "Use another browser." :evil:
Since your profile here is publicly viewable, it is not a secret that you're a programmer/analyst yourself. Please tell me you'd never code a site so poorly that *navigating within the same site* (especially a secure one :o ) would produce XSS messages...
[rant] Lazy, sloppy, or downright incompetent site designers seem to be pandemic -- and IMHO, banks and financial institutions [url=http://forums.informaction.com/viewtopic.php?p=34267#p34267]are[/url] the [url=http://forums.informaction.com/viewtopic.php?p=34557#p34557]worst[/url]. [/rant]