Question 1
Q1A financial services company is developing a Java application that processes international payments and must handle user data containing various Unicode characters. To prevent Cross-Site Scripting (XSS), a developer implements a filter using String.replace() to remove occurrences of and from all input fields. Which of the following statements best describes the primary security flaw in this approach?
Show answer & explanation
Correct answer: B
Blacklist validation is fundamentally flawed because it is impossible to anticipate all possible malicious inputs. Attackers can use various techniques like case variations ( ), different encodings, or alternative vectors like to bypass simple string replacement. The correct approach is to use a combination of whitelist validation for input and context-aware output encoding.