#27
May 04

Cross Site Scripting

Another common security issue is cross site scripting. In this episode you will see why it is so important to escape any HTML a user may submit.
Tags: security views
Download (19.4 MB, 5:50)
alternative download for iPod & Apple TV (9.3 MB, 5:50)
<%=h comment.content %>
CGI::escapeHTML(...)

16 comments:

Xilo32 May 04, 2007 at 00:28

Thanks for another great screencast tutorial!

Keep up the great work!


InMan May 04, 2007 at 00:48

Thanks. I missed this security hole in many places :).


eTrueke May 04, 2007 at 02:39

Thanks again!


Slaptijack May 04, 2007 at 05:31

Good topic, Ryan. Cross-site scripting is such a common problem and really needs plenty of attention.


Ryan Bates May 04, 2007 at 07:30

Please let me know if you are unable to transfer the iPod version to your iPod/Apple TV. I may have got the compression settings incorrect or something.


David Parker May 04, 2007 at 08:17

Ryan, I haven't yet tried the download for iPod option, but I was just curious: what's the difference between that version and the regular one? Is it just more compressed?


Ryan Bates May 04, 2007 at 08:56

Good question. It's 640x480 instead of 800x600 and the compression doesn't look as nice, so if you don't need to play it back on an iPod/Apple TV it's definitely better to stick with the higher quality version.


David Parker May 04, 2007 at 12:05

Thanks Ryan. I'll probably start downloading the iPod versions though... that way I can take the casts with me on trips (Sadly, I don't have a laptop yet). As much as I like the higher quality, I find no reason to download the videos twice (and I might as well save you a little bandwidth). Thanks and keep up the good work!


Sergio de la Garza May 04, 2007 at 16:58

Thanks Ryan for these excelent screencasts.

Keep it up

congrats from México.


Ryan Bates May 04, 2007 at 20:43

For those interested, the iPod format should be working now. Sorry about the incompatable file format.


Terrence May 04, 2007 at 23:19

Hey Ryan,
I was JUST about to whine about the iPod version. :) Thanks for another great tute and for reading my mind!


peanut May 05, 2007 at 01:18

Very useful issue!


Andrew Parker May 09, 2007 at 00:09

I find the ipod versions hard to read because they're too blurry (the normal versions are fantastic, incredibly clear!).
I suppose that's because the resolution has been reduced, but is it also because of higher compression? h264 should be able to do clear video, is it possible to turn up the bitrate?

Anyway, these railscasts are very useful, keep up the great work!


albemuth Oct 31, 2007 at 11:26

<script>alert('Hi!')</script> :D


http://www.linuxjobworld.com Dec 10, 2007 at 08:18

cool...downloading them right now..


Snailrails Feb 04, 2008 at 07:22

Hey, I wrote a quick informative tutorial about XSS on http://www.snailrails.com/2008/1/cross-site-scripting.

Check it out for some more information.

Add your comment:

(required)

(not displayed)

(SKIP THIS ONE)


(required)

subscribe:
sponsored by:
if you want to help:
required:
Get Quicktime Player