CSS: The bomb inside your inbox(portswigger.net) |
CSS: The bomb inside your inbox(portswigger.net) |
> One of the best methods to protect against these attacks is strict isolation. If you isolate the email message using sandboxed iframes you restrict the ability to break out of trusted boundaries. If you are not using sandboxed iframes, always be careful when allowing custom attributes and check for HTML/CSS gadgets. Use a strict allow list of characters when validating keywords and names to avoid mutation when using the CSSOM.
iframes should be the first layer of any defense-in-depth against user-submitted content.
Haven't tried it yet though, done some reading but don't know enough to be sure their proposed paradigm is valid.
Yeah no shit.
But when most of the articles submitted here don't work without JavaScript, this comment seems really irrelevant.
I guess my question would be why does something so benign and common aggravate you so much? That feels like an exhausting way to live.
Oh that's all, is it?