289 karma · joined December 16, 2011
Again this is far from ideal, but also not readily exploitable by attackers that couldn't already access the data.
https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_She...
Blacklists are only acceptable if you do it in addition to contextual encoding wherever you emit user controlled data, and even then a much stronger protection would be to whitelist acceptable characters. Either way, contextual encoding whenever you emit user data is the only real protection. --And even then it's not a good fallback protection, a strong Content-Security-Policy should be your fallback protection.
> Unless you're intending for your user to post HTML, or math inequalities, or diff patches - there's no reason to allow angle brackets on a form post.
Form posts are not the only vector for XSS, any HTTP request can be potentially exploited to perform XSS (and any part of an HTTP request), doesn't matter if it's a Form, an AJAX request, an HTTP header value, or a GET parameter, they're all potential attack vectors.
“First of all, VR displays are a little too cumbersome. It has to be much more elegant, being connected by a wire has to be solved. The resolution has to be a lot higher. The physical worlds do not behave according to the laws of physics. The environment you’re in isn’t beautiful enough. We’re going to be solving this problem for the next 20 years.”
"Solving over 20 years" / "20 years from being solved" are very different things.
JSConsole -http://jsconsole.com/ Weinre - https://people.apache.org/~pmuellr/weinre/docs/1.x/1.5.0/