News Feed
Jobs Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Chris Shiflett's Blog:
Google XSS and Evil Character Encoding
December 22, 2005 @ 06:19:39

On his blog today, Chris Shiflett has two posts about a problem with Google and a Cross-site Scripting attack that it's vulnerable to.

From this post: The recent cross-site scripting (XSS) vulnerability discovered in Google perfectly illustrates why character encoding matters. This example demonstrates how to use PHP's htmlentities() with the optional third argument that indicates the character encoding.

By way of demonstration, he provides a little PHP script that makes a request in a different character encoding than Google can handle. Coupled with the small response from Google, a UTF-7 character sent to certain browsers could be interpreted and executed.

In this second post, he answers a question from the comments - "how will this effect my site?"

Rather than offer another vague answer, I decided to provide a very simple proof of concept that demonstrates how character encoding inconsistencies can bite you. Google's vulnerability has of course been fixed, but with a simple PHP script, we can reproduce the situation.

The script, though escaped, still causes a Javascript popup box to show when the page is loaded - all due to a lack of improper character encoding handling...

0 comments voice your opinion now!
shiflett google xss character encoding shiflett google xss character encoding


blog comments powered by Disqus

Similar Posts

Secubos.com: Cross-Site Scripting Vulnerability in phpFaber

Zend Developer Zone: Notes from the Web Builder 2.0 Conference

PHPClasses.org: Participate in the Lately in PHP podcast in Video with Google Hangouts

Community News: WordPress 2.0.6 Released to Resolve Security Issues

Chris Shiflett\'s Blog: Google XSS and Evil Character Encoding


Community Events











Don't see your event here?
Let us know!


package opinion framework composer support application performance security install hhvm language facebook release unittest component hack symfony2 introduction podcast database

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework