Duplicate of:
This is a security question.
What should I look for in URL that prevents hacking?
Is there a way to execute javascript by passing it inside a URL?
As you can see I’m pretty new to this concept.
Any good posts on this stuff?
Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.
Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.
Lost your password? Please enter your email address. You will receive a link and will create a new password via email.
Please briefly explain why you feel this question should be reported.
Please briefly explain why you feel this answer should be reported.
Please briefly explain why you feel this user should be reported.
I don’t believe you can hack via the URL. Someone could try to inject code into your application if you are passing parameters (either GET or POST) into your app so your avoidance is going to be very similar to what you’d do for a local application.
Make sure you aren’t adding parameters to SQL or other script executions that were passed into the code from the browser without making sure the strings don’t contain any script language. Search the next for details about injection attacks for the development platform you are working with, that should yield lots of good advice and examples.