Web
Applica+on
Pentes+ng
Vivek
Ramachandran
SWSE,
SMFE,
SPSE,
SISE,
SLAE,
SGDE
Course
Instructor
Cer+fica+ons:
hGp://www.securitytube-‐training.com
Pentester
Academy:
hGp://www.PentesterAcademy.com
©SecurityTube.net
HTML
Injec+on
–
Bypass
Filters
©SecurityTube.net
Filters
/
Escape
HTML
©SecurityTube.net
Why
this
confusion?
hGp://bugs.python.org/issue9061
©SecurityTube.net
Can
it
do
more?
hGps://wiki.python.org/moin/EscapingHtml
©SecurityTube.net
Filter
Code
in
Applica+on
©SecurityTube.net
Pentester
Academy
©SecurityTube.net