From: Jeff King Date: Tue, 13 Nov 2012 17:04:52 GMT Subject: Re: [BUG] gitweb: XSS vulnerability of RSS feed Message-ID: <20121113170452.GE20361@sigill.intra.peff.net> In-Reply-To: On Tue, Nov 13, 2012 at 09:44:06AM -0500, Drew Northup wrote: > I don't buy the argument that we don't need to clean up the input as > well. There are scant few of us that are going to name a file > "" in this world (I am > probably one of them). Input validation is key to keeping problems > like this from coming up repeatedly as those writing the guts of > programs are typically more interested in getting the "assigned task" > done and reporting the output to the user in a safe manner. Oh, you absolutely do need to clean up the input side. And we do. Notice how validate_pathname cleans out dots that could allow an attacker to do a "../../etc/passwd" attack. But the input validation is _different_ than the output escaping. We are turning arbitrary junk from the user into something we know is safe to treat as a filename. Our goal is protecting the filesystem and the server, and we do that already. Protecting the browser on output is a different problem, and happens only when we are sending to the browser. As far as "people will not use