<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>What's wrong with ASP.NET?  HTML encoding</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx</link><description>The problem Back when ASP.NET was first introduced, I had pretty high hopes that the new controls would offer support for automatic HTML encoding. Unfortunately, there was very little of this, and most of it was more than a bit lukewarm (more on this</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Amazing, and undocumented</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1728124</link><pubDate>Tue, 29 Sep 2009 08:21:41 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1728124</guid><dc:creator>Anthony Berglas</dc:creator><description>&lt;p&gt;I just thought I had better check, and was also shocked that label does not encode. &amp;nbsp;And none of the examples mention it. &amp;nbsp;And this is 2009!&lt;/p&gt;
&lt;p&gt;Inconsistent is even worse than none. &amp;nbsp;Thanks for the table.&lt;/p&gt;
&lt;p&gt;I think we need the PHP hack -- never accept odd characters in input, and hope all input comes through such a filter. &amp;nbsp;PHP abandoned that some years ago for good reason.&lt;/p&gt;
&lt;p&gt;I hope LINQ does a better job of SQL injection attacks.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1728124" width="1" height="1"&gt;</description></item><item><title>re: What's wrong with ASP.NET?  HTML encoding</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1699986</link><pubDate>Mon, 13 Jul 2009 07:29:14 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1699986</guid><dc:creator>Shocked</dc:creator><description>&lt;p&gt;I&amp;#39;m shocked the Label control doesn&amp;#39;t encode.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1699986" width="1" height="1"&gt;</description></item><item><title>re: What's wrong with ASP.NET?  HTML encoding</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1646544</link><pubDate>Wed, 03 Sep 2008 00:16:04 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1646544</guid><dc:creator>Sacha</dc:creator><description>&lt;p&gt;You might want to review my post about ASP.NET encoding.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="https://blogs.msdn.com/sfaust/archive/2008/09/02/which-asp-net-controls-automatically-encodes.aspx"&gt;blogs.msdn.com/.../which-asp-net-controls-automatically-encodes.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1646544" width="1" height="1"&gt;</description></item><item><title>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549580</link><pubDate>Fri, 21 Mar 2008 21:21:55 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549580</guid><dc:creator>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Scott Hanselman&amp;#39;s Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549580" width="1" height="1"&gt;</description></item><item><title>The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549579</link><pubDate>Fri, 21 Mar 2008 21:21:53 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549579</guid><dc:creator>Scott Hanselman's Computer Zen</dc:creator><description>&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549579" width="1" height="1"&gt;</description></item><item><title>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549578</link><pubDate>Fri, 21 Mar 2008 21:20:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549578</guid><dc:creator>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Scott Hanselman&amp;#39;s Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549578" width="1" height="1"&gt;</description></item><item><title>The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549577</link><pubDate>Fri, 21 Mar 2008 21:20:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549577</guid><dc:creator>Scott Hanselman's Computer Zen</dc:creator><description>&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549577" width="1" height="1"&gt;</description></item><item><title>The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549554</link><pubDate>Fri, 21 Mar 2008 20:36:28 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549554</guid><dc:creator>ASPInsiders</dc:creator><description>&lt;p&gt;And so, Dear Reader, I present to you twenty-first in a infinite number of posts of &amp;amp;quot; The Weekly&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549554" width="1" height="1"&gt;</description></item><item><title>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549549</link><pubDate>Fri, 21 Mar 2008 20:28:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549549</guid><dc:creator>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Scott Hanselman&amp;#39;s Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549549" width="1" height="1"&gt;</description></item><item><title>The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549548</link><pubDate>Fri, 21 Mar 2008 20:28:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549548</guid><dc:creator>Scott Hanselman's Computer Zen</dc:creator><description>&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549548" width="1" height="1"&gt;</description></item><item><title>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549544</link><pubDate>Fri, 21 Mar 2008 20:26:37 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549544</guid><dc:creator>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Scott Hanselman&amp;#39;s Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549544" width="1" height="1"&gt;</description></item><item><title>The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549543</link><pubDate>Fri, 21 Mar 2008 20:26:34 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549543</guid><dc:creator>Scott Hanselman's Computer Zen</dc:creator><description>&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549543" width="1" height="1"&gt;</description></item><item><title>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549539</link><pubDate>Fri, 21 Mar 2008 20:14:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549539</guid><dc:creator>Scott Hanselman's Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Scott Hanselman&amp;#39;s Computer Zen - The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549539" width="1" height="1"&gt;</description></item><item><title>The Weekly Source Code 21 - ASP.NET MVC Preview 2 Source Code</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1549538</link><pubDate>Fri, 21 Mar 2008 20:14:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1549538</guid><dc:creator>Scott Hanselman's Computer Zen</dc:creator><description>&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1549538" width="1" height="1"&gt;</description></item><item><title>re: What's wrong with ASP.NET?  HTML encoding</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1388425</link><pubDate>Sun, 09 Dec 2007 13:16:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1388425</guid><dc:creator>calinoiu</dc:creator><description>&lt;p&gt;Thanks for the heads-up about the single-line text box encoding. &amp;nbsp;Given that the double-encoding example in the &amp;quot;Workarounds&amp;quot; section depends on attribute-encoding in a single-line textbox, I must have been completely asleep at the wheel when I populated that line of the table. &amp;nbsp;It's fixed now...&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1388425" width="1" height="1"&gt;</description></item><item><title>re: What's wrong with ASP.NET?  HTML encoding</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#1012400</link><pubDate>Mon, 09 Jul 2007 18:56:59 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1012400</guid><dc:creator>Sachin</dc:creator><description>&lt;p&gt;Errata : (for ASP.NET 2.0)&lt;/p&gt;
&lt;p&gt;single-line TextBox value is attribute encoded.&lt;/p&gt;
&lt;p&gt;multi-line TextBox value is html encoded.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1012400" width="1" height="1"&gt;</description></item><item><title>re: What's wrong with ASP.NET?  HTML encoding</title><link>http://msmvps.com/blogs/calinoiu/archive/2006/06/13/what-s-wrong-with-asp-net-html-encoding.aspx#998041</link><pubDate>Mon, 02 Jul 2007 16:29:59 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:998041</guid><dc:creator>Nick</dc:creator><description>&lt;p&gt;I&amp;#39;m running into the same problem with a script I&amp;#39;m designing. &amp;nbsp;This is very agrivating and I hope they do fix this is 3.0.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=998041" width="1" height="1"&gt;</description></item></channel></rss>