org.owasp.html.examples
public class EbayPolicyExample extends java.lang.Object
eBay (http://www.ebay.com/) is the most popular online auction site in the
universe, as far as I can tell. It is a public site so anyone is allowed to
post listings with rich HTML content. It's not surprising that given the
attractiveness of eBay as a target that it has been subject to a few complex
XSS attacks. Listings are allowed to contain much more rich content than,
say, Slashdot- so it's attack surface is considerably larger. The following
tags appear to be accepted by eBay (they don't publish rules):
<a>
,...
Modifier and Type | Field and Description |
---|---|
static com.google.common.base.Function<HtmlStreamEventReceiver,HtmlSanitizer.Policy> |
POLICY_DEFINITION |
Constructor and Description |
---|
EbayPolicyExample() |
Modifier and Type | Method and Description |
---|---|
static void |
main(java.lang.String[] args) |
public static final com.google.common.base.Function<HtmlStreamEventReceiver,HtmlSanitizer.Policy> POLICY_DEFINITION
Copyright © 2014 OWASP. All Rights Reserved.