code.google.com home

org.owasp.html.examples
Class EbayPolicyExample

java.lang.Object
  extended by org.owasp.html.examples.EbayPolicyExample

public class EbayPolicyExample
extends java.lang.Object

Based on the AntiSamy EBay example.

eBay (http://www.ebay.com/) is the most popular online auction site in the universe, as far as I can tell. It is a public site so anyone is allowed to post listings with rich HTML content. It's not surprising that given the attractiveness of eBay as a target that it has been subject to a few complex XSS attacks. Listings are allowed to contain much more rich content than, say, Slashdot- so it's attack surface is considerably larger. The following tags appear to be accepted by eBay (they don't publish rules): <a>,...


Field Summary
static PolicyFactory POLICY_DEFINITION
           
 
Constructor Summary
EbayPolicyExample()
           
 
Method Summary
static void main(java.lang.String[] args)
           
 
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
 

Field Detail

POLICY_DEFINITION

public static final PolicyFactory POLICY_DEFINITION
Constructor Detail

EbayPolicyExample

public EbayPolicyExample()
Method Detail

main

public static void main(java.lang.String[] args)
                 throws java.io.IOException
Throws:
java.io.IOException

code.google.com home