CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy
A security analyst is evaluating a web application for potential vulnerabilities. The application takes user-submitted HTML content for blog posts and displays it directly on other users' screens. The analyst notices that a user can submit the following content: `<script>alert('XSS');</script>`, and it executes in other users' browsers. Which secure coding practice, if properly implemented, would prevent this specific vulnerability?
- AError Handling
- BOutput Encoding
- CParameterized Queries
- DInput Validation
Show answer & explanationAnswer & explanation
Correct answer: B. Output Encoding
The vulnerability described is Cross-Site Scripting (XSS), where malicious client-side script is injected and executed in a user's browser. Output Encoding prevents this by converting special characters (like <, >, &) into their HTML entity equivalents before rendering, so the browser interprets them as text rather than executable code.
Why the other options are wrong
- A. Error Handling manages unexpected program behavior and does not directly prevent XSS vulnerabilities.
- C. Parameterized Queries prevent SQL Injection vulnerabilities, which are server-side database attacks, not client-side script execution.
- D. Input Validation checks if input meets expected criteria, but it's often difficult to perfectly validate all potentially malicious HTML without inadvertently breaking legitimate content. It's a good practice but less direct for preventing XSS than output encoding.
Output Encoding
Output encoding is a secure coding practice that converts special characters in user-supplied data into their entity equivalents before the data is displayed or used in a specific context (e.g., HTML, JSON, XML).
- Prevents Cross-Site Scripting (XSS) by ensuring malicious scripts are interpreted as text, not code.
- Different contexts require different encoding schemes (e.g., HTML entity encoding, URL encoding, JavaScript escaping).
- Must be applied 'just in time' before data is rendered to the user.
Memory trick: Encode your Output: Don't let bad scripts escape into your browser's 'output'.