Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > ASP .Net > Help with validateRequest (XSS)

Thread Tools

Help with validateRequest (XSS)

Posts: n/a
I have the validateRequest set to true in the web config. I have
written my own iHTTPHandler class and configured the web.config to use
it for all requests to app.aspx. when I try to navigate to that page
with a parameter of xss=<xssmc> the request is processed wothout an
issue. If I try the same parameter on a page that is not handled by my
class, an exception is thrown saying that there is a potentialy harmful
request. I have found that if I call to the request objects
ValidateInput method in my handler, I will get the same exception when
I access the request parameters. Am I correct in thinking the default
aspx handler call this method also. I have searched using reflector but
I cannot find a call to the ValidateInput method anywhere in the
System.Web assembly...


Reply With Quote

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
About validateRequest Benny ASP .Net 1 02-20-2004 01:50 PM
validateRequest directive Tascien ASP .Net 0 02-17-2004 06:21 AM
ValidateRequest Shaun Dore ASP .Net 1 11-05-2003 02:27 AM
set validateRequest attribute at runtime Shaun Dore ASP .Net 1 11-03-2003 10:08 PM
ValidateRequest="false" error Martin Colmenares ASP .Net 0 06-27-2003 06:08 PM