微软AntiXSS替代 [英] Microsoft AntiXSS Alternative

查看:366
本文介绍了微软AntiXSS替代的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

微软的AntiXSS库已经 6个月,它看起来抛弃(可能会或可能不会正式是的情况)。由于与previous版本的安全问题,这是不是安全回滚到早期版本。是否有AntiXSS一般与微软(特别是MVC)堆栈?

Microsoft's AntiXSS library has been broken for 6 months and it looks abandoned (that may or may not officially be the case). Due to a security issue with previous versions, it is not safe to rollback to an earlier release. Are there any good actively developed alternatives for AntiXSS and web security in general when working with the Microsoft (specifically MVC) stack?

推荐答案

有消毒剂航运新XSS与AJAX控件工具包的2012年6月发布。该工具包最初是使用Microsoft防XSS库一样,所以他们经历了同样的问题。新的消毒剂是基于该HtmlAgilityPack

There's a new xss sanitizer shipping with the June 2012 release of the ajax control toolkit. The toolkit was originally using the microsoft anti xss library as well, so they experienced the same problems. The new sanitizer is based off the HtmlAgilityPack

请参阅http://stephenwalther.com/archive/2012/06/25/announcing-the-june-2012-release-of-the-ajax-control-toolkit.aspx

这篇关于微软AntiXSS替代的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆