As a temporary quick fix to mitigate the major risk while working on the permanent fix for XSS Vulnerability in a very large code base, I’m looking for a pre-existing XSS prevention blacklist that does a reasonable job of protecting against XSS.
Preferably a set of Regular Expressions. I’m aware of plenty of cheat sheets for testing and smoke tests etc, what I’m looking for is pre-tuned regexps for blocking the attacks.
I am fully aware that the best way is output escaping or if you need some markup from users to use whitelisting. But, with the size of the code base, we need something in quick to reduce the immediate footprint of the vulnerability and raise the bar whilst working on the real solution.
Is anyone aware of a good set?
I realise this may not be a direct answer to your question, but ASP.NET developers in a similar situation may find this useful:
Microsoft Anti-Cross Site Scripting Library V1.5