[Esd-l] Removal of HTML comments

John D. Hardin jhardin at impsec.org
Sat Jan 18 09:30:00 PST 2003

On Sat, 18 Jan 2003, Bill Larson wrote:

> How long do you think it will be once a virus writer realizes that
> they can bypass things like the sanitizer using this method that
> it will take for a virus of this nature to appear. I know I would
> much rather be proactive than retroactive.

I don't think it's too likely. Bypassing the sanitizer using embedded
comments would be something along the lines of:


...and that wouldn't work. An HTML script has to be valid HTML. The
HTML parser doesn't pull out comments before parsing for other tags.
(of course, bonehead design like that *would* allow the sanitizer to
be bypassed.)

Let me think about it a bit.

