ETExamTower
Q19Application Deployment and SecurityMultiple answers

A web application is vulnerable to cross-site scripting. Which two methods can mitigate this issue? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
B
50% (4)
E
50% (4)
A
0% (0)
C
0% (0)
D
0% (0)
Discussion · 12
32
B. Restrict user input to acceptable characters. E. Strip all HTML/XML tags from user input.
3
I agree with PopLife on this: B. Limit user input to acceptable characters. This could be related to XSS Filters/Sanitization, where you take the untrusted user input and strip out anything that is not permitted. E. Remove all HTML/XML tags from user input. This might be related to the concept of XSS Escaping. Like HTML, CSS, XML, Javascripts Escaping. https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
B, E 3
Selected Answer: BE B and E
2
I agree with PopLife, the answer should be 'B & E'
2
My logic on this one is "a web app is susceptible" meaning it can happen. XSS can't happen with drop downs. So it's not susceptible. But technically you're right that drop downs would eliminate it, but I'm still sticking with B&E here too. Maybe you need user input for something?
2
Without extra code checks, dropdowns only limit what a user can enter in the browser. They could still send a crafted request (with postman/curl) with invalid data.
B, E 2
Selected Answer: BE B and E are correct: "To mitigate this attack, the easiest approach is to escape any user input, both when you receive it from the user and when you send data to other users. For example, replacing the < character with &lt; or &#60; for the web content would disable all HTML tags. In Python, this can be done with the standard html.escape() and html.unescape() functions. Sometimes some HTML tags are allowed, so escaping them all is not an option. In that case, sanitization is a suitable solution. Sanitization processes untrusted user input and runs it through the filter, which allows valid content but strips anything that is not permitted. For example, it may allow <A>, <IMG>, <B> HTML tags but strip any other tags."
B, E 2
Selected Answer: BE Correct answers: B & E B. Restrict user input to acceptable characters. E. Strip all HTML/XML tags from user input. https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
1
Why not use only drop-downs, not working? Using drop-downs can totally eliminate the chance of user input.
1
Thanks flambadone for the great explanation, yes, the susceptible part makes sense here
1
Exactly this. Press F12 in any browser and change the dropdown into a text field. Now you can send any data you want if the server doesn't validate the data
1
B. Restrict user input to acceptable characters. E. Strip all HTML/XML tags from user input.