DEV Community

Discussion on: Where can I find regex to prevent code injection?

Collapse
 
sudoehtisham profile image
Ehtisham-sudo

There are so many payloads and maybe your regex can stop few of them but at the same time the attacker has ability to understand what type of filtering is on place. Later he/she can modify the payload according to that. But this method looks more applicable. I am not a developer just a guy who is into wen application security and penetration testing

1: block all the common payloads to prevent script kiddies
2: encoding the user input (search queries, )