EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium

A web developer wants to implement a robust input validation mechanism to prevent various web application attacks. Which validation approach is generally considered the most secure and effective?

  1. AWhitelisting known good input patterns.
  2. BClient-side validation only.
  3. CBlacklisting known malicious input patterns.
  4. DValidation using regular expressions without anchoring.
Show answer & explanation

Correct answer: A. Whitelisting known good input patterns.

Whitelisting (also known as 'allowlisting') is considered the most secure input validation approach. It explicitly defines what is allowed and rejects everything else, making it much harder for attackers to bypass compared to blacklisting, which tries to define what is forbidden and can be incomplete.

Why the other options are wrong

  • B. Client-side validation is for user experience, not security; it can be easily bypassed by an attacker.
  • C. Blacklisting is prone to bypass by new or encoded attack vectors, as it's difficult to list all possible malicious inputs.
  • D. Regular expressions are useful, but without proper anchoring (e.g., `^` and `$`), they can allow partial matches that could still be malicious.

Input Validation (Whitelisting)

A security practice where only explicitly defined 'good' input patterns are accepted, and all other input is rejected.

  • More secure than blacklisting.
  • Reduces the attack surface significantly.
  • Applicable to various input types: strings, numbers, file uploads.

Memory trick: Whitelist means 'only the good guys get in'.

More Web Application Hacking questions