XSS Encoding in JavaScript Context

Viewed 173

I am taking a user input in C++ code and passing it into a JS function. It's causing XSS. The code below is a simplified version of the problem. If you run it, it will show an alert. Will HTML encoding fix it or is there any other encoding for this scenario?

<html>
<head>
<SCRIPT language="javascript">

function f1(id1, id2, flag){}

<!-- alert(1) is user input that was passed into this function  -->
f1(768, alert(1), true);

</SCRIPT>
</head><body></body></html>
1 Answers

I'm assuming that you are generating JavaScript code. You can't use html entities to encode or escape dangerous characters. If you were trying to encode the () characters you are likely to generate JS syntax errors.

Don't try to detect function calls by looking for (…). This simple hack will bypass your check:

alert`"gotcha!"`

You could quote alert(1) so that it becomes a string "alert(1)" but then an attacker could simply submit this as input: ", alert(1), " which would produce something like that: (and still execute code)

f1(768, "", alert(1), "", true);

In cases like yours I would look into creating a sandboxed environment where code can run without privileged access.

Related