Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If your system accepts 'foo" onmouseover="alert(1)' as a username, you've got bigger problems.

Technically that shouldn't be a problem. I can put that in HTML, in URL, in the database. I can even make directory with that name and use it in shell scripts — as long as every one of them uses correct escaping.

Bobby Tables is welcome on my systems.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: