Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > ASP .Net > ASP .Net Security > What characters are allowed by validateRequest page directive?

Reply
Thread Tools

What characters are allowed by validateRequest page directive?

 
 
Ken Sturgeon
Guest
Posts: n/a
 
      06-11-2007
I've seen several articles that indicate that if the page directive
validateRequest="True" (shown below) that the user input is validated
against a hard coded list of characters. What I cannot find is any
documentation that shows the hard coded list of characters. Does anyone know
where I can find this list or know exactly what's in the list?

<% @ Page validateRequest="True" %>


Thanks

-- Ken Sturgeon

 
Reply With Quote
 
 
 
 
Dominick Baier
Guest
Posts: n/a
 
      06-11-2007
well - besides having a look with reflector -

it is mostly

< followed by a-z

and

< followed by #

there is a third one i forgot.


-----
Dominick Baier (http://www.leastprivilege.com)

Developing More Secure Microsoft ASP.NET 2.0 Applications (http://www.microsoft.com/mspress/books/9989.asp)

> I've seen several articles that indicate that if the page directive
> validateRequest="True" (shown below) that the user input is validated
> against a hard coded list of characters. What I cannot find is any
> documentation that shows the hard coded list of characters. Does
> anyone know where I can find this list or know exactly what's in the
> list?
>
> <% @ Page validateRequest="True" %>
>
> Thanks
>



 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Why defining a constant in a method is not allowed but usingself.class.const_set is allowed? IƱaki Baz Castillo Ruby 13 05-01-2011 06:09 PM
html markup allowed in textbox even though validaterequest=true Andy Fish ASP .Net Web Controls 1 10-27-2004 08:42 AM
validateRequest="false" not working in web.config or page directive Tim Zych ASP .Net 2 05-16-2004 04:58 PM
Re: validateRequest=&quot;false&quot; not working in web.config or page directive Phil Winstanley [Microsoft MVP ASP.NET] ASP .Net 0 05-16-2004 09:23 AM
@Page validateRequest And UserControls =?Utf-8?B?UmF5IFdpbGxpYW1z?= ASP .Net 4 05-07-2004 07:03 AM



Advertisments