{"id":63244,"date":"2022-02-16T09:38:40","date_gmt":"2022-02-16T17:38:40","guid":{"rendered":"https:\/\/github.blog\/?p=63244"},"modified":"2022-02-25T10:45:40","modified_gmt":"2022-02-25T18:45:40","slug":"encoding-escaping-untrusted-data-prevent-injection-attacks","status":"publish","type":"post","link":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/","title":{"rendered":"Encoding and escaping untrusted data to prevent injection attacks"},"content":{"rendered":"<p><em>This is part five of GitHub Security Lab\u2019s <a href=\"https:\/\/github.blog\/2021-12-06-write-more-secure-code-owasp-top-10-proactive-controls\/\">series on the OWASP Top 10 Proactive Controls<\/a>, where we provide practical guidance for OSS developers and maintainers on improving your security posture.<\/em><\/p>\n<hr>\n<p>A vast majority of injection attacks come from what we would term <em>tampered data<\/em>: unexpected data or formatting in inputs with the intent of discovering or exploiting vulnerabilities. In this post, I\u2019ll discuss ways to defend yourself using guidance from OWASP Top 10 Proactive Controls C4: Encode and Escape Data&#8212;including the \u201cwhy\u201d and \u201cwhat\u201d of that control.<\/p>\n<h2 id=\"encoding-and-injection-according-to-owasp\"><a class=\"heading-link\" href=\"#encoding-and-injection-according-to-owasp\">Encoding and injection according to OWASP<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>From the OWASP document about this control:<\/p>\n<blockquote><p>\n  <strong>Encoding<\/strong> and escaping are defensive techniques meant to stop injection attacks.\n<\/p><\/blockquote>\n<p>Until <a href=\"https:\/\/owasp.org\/www-project-top-ten\/2017\/Top_10\">2017<\/a>, OWASP\u2019s list of Top 10 Risks listed cross-site scripting (XSS) separately from &#8220;injection.&#8221; There are many (myself included) that consider XSS a form of injection. So, saying that output encoding prevents injection attacks is accurate in that light.<\/p>\n<h2 id=\"injection-attacks-encoding-and-interpreters\"><a class=\"heading-link\" href=\"#injection-attacks-encoding-and-interpreters\">Injection attacks, encoding and interpreters<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<aside class=\"post-aside--small float-sm-right col-sm-5 col-md-6 col-lg-5 my-5 my-sm-2 ml-sm-4 ml-lg-6\"><p class=\"h6-mktg gh-aside-title\">What&#039;s the difference between escaping and encoding?<\/p><p>I&#8217;ll use the two terms largely interchangeably in this post. In short, the intent is that escaping or encoding helps render unsafe external inputs safe in an executable context.<\/p>\n<\/aside>\n<p>The real danger of injection attacks is that they are usually of a what-you-see-is-NOT-what-you-get nature. Using different encoding schemes that our interpreters will often \u201chelpfully\u201d decode later, attackers bypass simple denylist approaches. I recall once (early in my security awareness days, still working as a software engineer) trying to defend against SQL injection (SQLi) by looking for unexpected commands like <code>DROP<\/code> or <code>INSERT<\/code> where they might not be expected. Similarly, some web applications have looked for <code>&lt;script&gt;<\/code> in inputs to defend against XSS. This sort of approach is fragile, difficult to maintain from a code perspective, and ineffective from a security perspective. Also, the real defense against SQLi is parameterized queries (which encode things for you, more on that later), but let\u2019s get back to encoding.<\/p>\n<p>Encoding can be used in attacks as well as defense. In an attack, a malicious user might send <code>%3Cscript%3E<\/code> instead of <code>&lt;script&gt;<\/code> to evade an oversimplified denylist employed as a defense. <em>Output encoding<\/em>, which I\u2019ll talk about shortly, is a defensive technique.<\/p>\n<p>In most cases, the helpful interpreter is your browser, but it could also be a command-line environment or other bit of software such as a database driver. The browser, and hence XSS, represents a large target surface for which output encoding is the prevention technique. I\u2019ll  also cover some other examples. Let\u2019s dig in on XSS first.<\/p>\n<h2 id=\"xss-and-output-encoding\"><a class=\"heading-link\" href=\"#xss-and-output-encoding\">XSS and output encoding<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p><a href=\"https:\/\/owasp.org\/www-community\/attacks\/xss\/\">Cross-site scripting (XSS)<\/a> is a vulnerability. When exploited, a malicious user injects their JavaScript to run in your browser in a malicious way and usually without your knowledge.<\/p>\n<p>The primary defense for XSS is &#8220;output encoding.&#8221; What does that mean? As an example, it means rendering a user input that was <code>&lt;<\/code> as <code>&amp;lt;<\/code> so that the input renders the <code>&lt;<\/code> on the page (viewable as content) and not as HTML source. In short, output encoding enables safe rendering of certain characters to the target interpreter.<\/p>\n<h3 id=\"context-is-key\"><a class=\"heading-link\" href=\"#context-is-key\">Context is key<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h3>\n<p>Context is very important in any discussion of XSS, browsers and encoding. In the browser, when we talk about context, we are primarily talking about where content is rendered. There are four contexts.<\/p>\n<ul>\n<li>HTML body (text between tags)<\/li>\n<li>HTML attributes (text within the tags)<\/li>\n<li>JavaScript (content between <code>&lt;script&gt;<\/code> and <code>&lt;\/script&gt;<\/code> tags)<\/li>\n<li>Cascading Style Sheets (CSS, content between <code>&lt;style&gt;<\/code> and <code>&lt;\/style&gt;<\/code> tags)<\/li>\n<\/ul>\n<p>Each context has its own encoding system. What this means is that you encode for JavaScript if you are outputting content between <code>&lt;script&gt; \u2026 &lt;\/script&gt;<\/code> tags. Likewise, you encode for HTML attributes between <code>&lt;<\/code> and <code>&gt;<\/code>, including tag names, attribute names, and attribute values. Encode for HTML body between tags and style between <code>&lt;style&gt;<\/code> tags.<\/p>\n<h3 id=\"encoding-properly-is-hard\"><a class=\"heading-link\" href=\"#encoding-properly-is-hard\">Encoding properly is hard<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h3>\n<p>The conventional and wise advice is to encode any data you output from an untrusted source (user or any external source) for the proper context (see above). This is a lot to get right.<\/p>\n<p>I once did training for a group that had an XSS finding in an app. We paused the training to dig into the affected application and code to do a hands-on exercise. When we checked the <code>git blame<\/code> and the comments, the XSS finding was introduced because of a change in the encoding context. It was encoded for JavaScript but was output into an HTML attribute. It had been encoded for a different context. The wrong encoding context opened the application up to the vulnerability. It\u2019s an easy mistake to make with potentially high impact.<\/p>\n<h3 id=\"bang-for-your-buck-for-application-developers\"><a class=\"heading-link\" href=\"#bang-for-your-buck-for-application-developers\">Bang for your buck for application developers<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h3>\n<p>So, when you are looking to defend against something as difficult and potentially pervasive as XSS by encoding, you need that encoding to be automatic. It should be something you don\u2019t have to think about constantly. OWASP lists it as a <a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cross_Site_Scripting_Prevention_Cheat_Sheet.html#bonus-rule-3-use-an-auto-escaping-template-system\">&#8220;bonus&#8221; rule<\/a> in their cross-site scripting prevention doc. I recommend starting here. Select your templating\/output engine such that encoding happens automatically for the right context. This means it would need to be explicitly overridden or disabled to make it insecure.<\/p>\n<h4 id=\"auto-encoding-frameworks-templating-engines\"><a class=\"heading-link\" href=\"#auto-encoding-frameworks-templating-engines\">Auto-encoding frameworks\/templating engines<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h4>\n<p>The OWASP doc regarding this control also says:<\/p>\n<blockquote><p>\n  Output encoding is best applied <em>just before<\/em> the content is passed to the target interpreter.\n<\/p><\/blockquote>\n<p>This is where frameworks and templating engines come into play. To make your anti-XSS life easier, use a framework that defaults to safely performing output encoding (which it will do as it passes content to the target interpreter). Here are a few:<\/p>\n<ul>\n<li><a href=\"https:\/\/reactjs.org\">ReactJS<\/a><\/li>\n<li><a href=\"https:\/\/docs.angularjs.org\/guide\/security\">AngularJS<\/a> (See the Angular <a href=\"https:\/\/docs.angularjs.org\/guide\/security\">security page<\/a> for more detail.)<\/li>\n<li><a href=\"https:\/\/handlebarsjs.com\">Handlebars<\/a><\/li>\n<li><a href=\"https:\/\/liquidjs.com\">LiquidJS<\/a><\/li>\n<li>Rails<\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-java-encoder\/\">Java Encoder Project<\/a> (From OWASP. Not an actual framework or template engine, but a well-written library to help in the fight against XSS.)<\/li>\n<li>.Net (Generally does well by default, but best to read their <a href=\"https:\/\/docs.microsoft.com\/en-us\/aspnet\/core\/security\/cross-site-scripting?view=aspnetcore-6.0\">security doc on the topic<\/a>.)<\/li>\n<\/ul>\n<p>Are these all guaranteed 100% XSS-free forever? No, but they have a solid record out of the box. This list is not exhaustive. If you would like to use something not on it, spend some time researching and maybe even ask around on whether that templating engine or library auto-escapes or performs output encoding according to the context by default.<\/p>\n<h4 id=\"dont-escape-the-escaping\"><a class=\"heading-link\" href=\"#dont-escape-the-escaping\">Don\u2019t escape the escaping<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h4>\n<p>When you do use a library or framework that handles the output encoding (or escaping) for you by default, don\u2019t bypass it. Some frameworks make it painfully obvious that you are doing it (like React and <code><a href=\"https:\/\/reactjs.org\/docs\/dom-elements.html#dangerouslysetinnerhtml\">dangerouslySetInnerHTML<\/a><\/code>). Others are more ambiguous, like Rails with <code><a href=\"https:\/\/apidock.com\/rails\/String\/html_safe\">html_safe<\/a><\/code>.  If you are unsure, read the docs.<\/p>\n<h2 id=\"other-encoding-or-escaping-scenarios\"><a class=\"heading-link\" href=\"#other-encoding-or-escaping-scenarios\">Other encoding or escaping scenarios<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>XSS and the browser are the prominent example of using encoding defensively. However, the \u2018front end\u2019 of web apps is not the only place you should use encoding to keep your applications safe.<\/p>\n<p>As I mentioned earlier, using parameterized queries is a form of encoding\/escaping potentially malicious input intended to cause SQL injection. A great explanation offered to me is that malicious input can be used to mix the control plane (the query) and the data plane (like values in the <code>WHERE<\/code> clause that you want to use from the user). This gives the user control over the control plane, allowing them to restructure or rewire the query. In the case of SQLi, this is most commonly done by introducing an unexpected <code>\u2019<\/code> to imbalance those planes. Parameterized queries automatically encode properly for you, negating that scenario of mixing control and data planes. Object-relational mapping (ORM) libraries do this by default in most cases too.<\/p>\n<p>In command injection, unexpected newline characters (<code>\\n<\/code>) may be introduced in order to bypass brittle validation. Normalize or encode the input to ensure that it represents a single line before validating it. Check the regular expression references for your language to ensure you are using single-line anchors in your validation. In general, this sort of encoding\/normalization is a good idea for code quality.<\/p>\n<h2 id=\"indirection-as-encoding\"><a class=\"heading-link\" href=\"#indirection-as-encoding\">Indirection as encoding<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>There will be times (namely when trying to prevent command injection) where you cannot encode (or regex) your way into safe usage. In such cases, consider indirection or abstraction. What this usually means is that you offer predefined values (like <code>1<\/code>,<code>2<\/code>,<code>3<\/code>,<code>4<\/code>) that map to other predefined values (maybe file names or paths, for example) where you process the input.<\/p>\n<h2 id=\"good-friction\"><a class=\"heading-link\" href=\"#good-friction\">Good friction<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>Encoding and escaping in addition to validation will always add some friction to your application or service, but not all friction is bad. In the case of attack prevention, think of it like brakes on the car: it\u2019s what allows you to go fast the rest of the time.<\/p>\n<hr>\n<p><em>Check out the rest of our <a href=\"https:\/\/github.blog\/2021-12-06-write-more-secure-code-owasp-top-10-proactive-controls\/\">OWASP Top 10 Proactive Controls series<\/a>, or follow <a href=\"https:\/\/twitter.com\/GHSecurityLab\">GitHub Security Lab on Twitter<\/a> for the latest in security research.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Practical tips on how to apply OWASP Top 10 Proactive Control C4.<\/p>\n","protected":false},"author":1958,"featured_media":63289,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gh_post_show_toc":"no","_gh_post_is_no_robots":"","_gh_post_is_featured":"no","_gh_post_is_excluded":"no","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"https:\/\/github.blog\/wp-content\/uploads\/2022\/01\/GitHub-Security_orange-square-icon-e1644630762962.png","_gh_post_sq_img_id":"62566","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"Click Here to Learn More","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false,"_links_to":"","_links_to_target":""},"categories":[91,3337],"tags":[1915,2294],"coauthors":[2508],"class_list":["post-63244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-web-application-security","tag-github-security-lab","tag-owasp-top-10-proactive-controls"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Encoding and escaping untrusted data to prevent injection attacks - The GitHub Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Encoding and escaping untrusted data to prevent injection attacks\" \/>\n<meta property=\"og:description\" content=\"Practical tips on how to apply OWASP Top 10 Proactive Control C4.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"The GitHub Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-16T17:38:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-02-25T18:45:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2022\/02\/Security-Community2@2x.png?fit=2400%2C1260\" \/>\n\t<meta property=\"og:image:width\" content=\"2400\" \/>\n\t<meta property=\"og:image:height\" content=\"1260\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Jason White\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2022\/02\/Security-Community2@2x.png?fit=2400%2C1260\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jason White\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/\"},\"author\":{\"name\":\"Jason White\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/e923f3af84df5ebe789cb8e9408f1786\"},\"headline\":\"Encoding and escaping untrusted data to prevent injection attacks\",\"datePublished\":\"2022-02-16T17:38:40+00:00\",\"dateModified\":\"2022-02-25T18:45:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/\"},\"wordCount\":1444,\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/Security-Community2@2x.png?fit=2400%2C1260\",\"keywords\":[\"GitHub Security Lab\",\"OWASP Top 10 Proactive Controls\"],\"articleSection\":[\"Security\",\"Web application security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/\",\"name\":\"Encoding and escaping untrusted data to prevent injection attacks - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/Security-Community2@2x.png?fit=2400%2C1260\",\"datePublished\":\"2022-02-16T17:38:40+00:00\",\"dateModified\":\"2022-02-25T18:45:40+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/e923f3af84df5ebe789cb8e9408f1786\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/Security-Community2@2x.png?fit=2400%2C1260\",\"contentUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/Security-Community2@2x.png?fit=2400%2C1260\",\"width\":2400,\"height\":1260},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/encoding-escaping-untrusted-data-prevent-injection-attacks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/github.blog\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Web application security\",\"item\":\"https:\\\/\\\/github.blog\\\/security\\\/web-application-security\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Encoding and escaping untrusted data to prevent injection attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/e923f3af84df5ebe789cb8e9408f1786\",\"name\":\"Jason White\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32460b6001303178ee9cbd2b5db630225c8eedca6672fdedf6b5eb6bf4a8e5a5?s=96&d=mm&r=g6742f5a11a2888335cc4318a71587a8d\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32460b6001303178ee9cbd2b5db630225c8eedca6672fdedf6b5eb6bf4a8e5a5?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32460b6001303178ee9cbd2b5db630225c8eedca6672fdedf6b5eb6bf4a8e5a5?s=96&d=mm&r=g\",\"caption\":\"Jason White\"},\"url\":\"https:\\\/\\\/github.blog\\\/author\\\/misfir3\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Encoding and escaping untrusted data to prevent injection attacks - The GitHub Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Encoding and escaping untrusted data to prevent injection attacks","og_description":"Practical tips on how to apply OWASP Top 10 Proactive Control C4.","og_url":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/","og_site_name":"The GitHub Blog","article_published_time":"2022-02-16T17:38:40+00:00","article_modified_time":"2022-02-25T18:45:40+00:00","og_image":[{"width":2400,"height":1260,"url":"https:\/\/github.blog\/wp-content\/uploads\/2022\/02\/Security-Community2@2x.png?fit=2400%2C1260","type":"image\/png"}],"author":"Jason White","twitter_card":"summary_large_image","twitter_image":"https:\/\/github.blog\/wp-content\/uploads\/2022\/02\/Security-Community2@2x.png?fit=2400%2C1260","twitter_misc":{"Written by":"Jason White","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/#article","isPartOf":{"@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/"},"author":{"name":"Jason White","@id":"https:\/\/github.blog\/#\/schema\/person\/e923f3af84df5ebe789cb8e9408f1786"},"headline":"Encoding and escaping untrusted data to prevent injection attacks","datePublished":"2022-02-16T17:38:40+00:00","dateModified":"2022-02-25T18:45:40+00:00","mainEntityOfPage":{"@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/"},"wordCount":1444,"image":{"@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2022\/02\/Security-Community2@2x.png?fit=2400%2C1260","keywords":["GitHub Security Lab","OWASP Top 10 Proactive Controls"],"articleSection":["Security","Web application security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/","url":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/","name":"Encoding and escaping untrusted data to prevent injection attacks - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/#primaryimage"},"image":{"@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2022\/02\/Security-Community2@2x.png?fit=2400%2C1260","datePublished":"2022-02-16T17:38:40+00:00","dateModified":"2022-02-25T18:45:40+00:00","author":{"@id":"https:\/\/github.blog\/#\/schema\/person\/e923f3af84df5ebe789cb8e9408f1786"},"breadcrumb":{"@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/#primaryimage","url":"https:\/\/github.blog\/wp-content\/uploads\/2022\/02\/Security-Community2@2x.png?fit=2400%2C1260","contentUrl":"https:\/\/github.blog\/wp-content\/uploads\/2022\/02\/Security-Community2@2x.png?fit=2400%2C1260","width":2400,"height":1260},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/security\/web-application-security\/encoding-escaping-untrusted-data-prevent-injection-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/github.blog\/security\/"},{"@type":"ListItem","position":3,"name":"Web application security","item":"https:\/\/github.blog\/security\/web-application-security\/"},{"@type":"ListItem","position":4,"name":"Encoding and escaping untrusted data to prevent injection attacks"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/github.blog\/#\/schema\/person\/e923f3af84df5ebe789cb8e9408f1786","name":"Jason White","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/32460b6001303178ee9cbd2b5db630225c8eedca6672fdedf6b5eb6bf4a8e5a5?s=96&d=mm&r=g6742f5a11a2888335cc4318a71587a8d","url":"https:\/\/secure.gravatar.com\/avatar\/32460b6001303178ee9cbd2b5db630225c8eedca6672fdedf6b5eb6bf4a8e5a5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/32460b6001303178ee9cbd2b5db630225c8eedca6672fdedf6b5eb6bf4a8e5a5?s=96&d=mm&r=g","caption":"Jason White"},"url":"https:\/\/github.blog\/author\/misfir3\/"}]}},"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pamS32-gs4","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/github.blog\/wp-content\/uploads\/2022\/02\/Security-Community2@2x.png?fit=2400%2C1260","_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/63244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/1958"}],"replies":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/comments?post=63244"}],"version-history":[{"count":44,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/63244\/revisions"}],"predecessor-version":[{"id":63286,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/63244\/revisions\/63286"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media\/63289"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=63244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/categories?post=63244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/tags?post=63244"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=63244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}