[owasp-antisamy] esapi encoder ldap query encoding

Jim Manico jim.manico at owasp.org
Thu Jul 7 04:10:51 EDT 2011


It's quite a complex topic. Please take a look at this thread

https://lists.owasp.org/pipermail/esapi-dev/2010-December/001459.html

- Jim


> Hi,
> 
> I'm looking for a way to encode LDAP queries ( to prevent injection
> attacks ).
> I understand that ESAPI encoder can do this , by calling encodeForLDAP ,
> encodeForDN )
> 
> However , i also understand that ESAPI is quite a large suit ( around 30
> jars) .
> Are all these libs required , when only using ESAPI encoder ?
> 
> Also, could you clarify which characters are escaped in case of
> encodeForLDAP , encodeForDN ?
> 
> Thanks,
> 
> Kind regards,
> Kenny,
> 
> 
> /
> 
> Dit bericht is onderworpen aan de voorwaarden beschikbaar op _onze
> website <http://www.colruytgroup.com/colruytgroup/static/disclaimer/nl.htm>_
> 
> Ce message est soumis aux conditions disponibles sur _notre site web
> <http://www.colruytgroup.com/colruytgroup/static/disclaimer/fr.htm>_
> 
> This message is subject to the terms and conditions available on _our
> website
> <http://www.colruytgroup.com/colruytgroup/static/disclaimer/eng.htm>_
> 
> /
> 
> 
> 
> _______________________________________________
> Owasp-antisamy mailing list
> Owasp-antisamy at lists.owasp.org
> https://lists.owasp.org/mailman/listinfo/owasp-antisamy



More information about the Owasp-antisamy mailing list