Secure › Module 4 › Lesson 1
Context Encoding
Encode output for HTML, JS, URL, and SQL contexts — in YOUR $TOY_APP templates.
Visual · context_encoding
Context encoding literacy. $MY_REPO only. Original Cyberlium.
Opening
The same string is safe in HTML and deadly in JavaScript — context decides encoding on code you ship.
Output encoding transforms data so it cannot break out of its rendering context: HTML entity encode for body text, JavaScript encode for inline scripts, URL encode for query parameters, SQL via bind parameters (not string escape alone). Cyberlium teaches context tables for $TOY_APP in $MY_REPO — not XSS payloads on live shop review forms. You will NOT 'practice encoding' by storing scripts in stranger SaaS comment fields or live product pages. Next: XSS Defense.
1. Context determines encoder
HTML body: < > &. Attribute: encode quotes. JavaScript string: escape for JS parser. URL: percent-encoding. SQL: bind parameters — separate from HTML encoding entirely.
Framework auto-escaping (React JSX, template engines) helps when you stay in safe APIs — document which contexts your $TOY_APP uses.
Command guide
Try these commands — Context determines encoder
═══ LINUX / BASH (Network & Reconnaissance Audit) ═══
Scan target host for open ports and service version signatures
Command — copy this
nmap -sS -sV -p 80,443,8080 -Pn ${LAB_HOST:-127.0.0.1}DNS and WHOIS reconnaissance on authorized domain
Command — copy this
dig +short A target.local dig +short MX target.local whois target.local 2>/dev/null | grep -iE "(Registrar|Creation Date|Name Server)" | head -6
Inspect HTTP headers for technology stack fingerprinting
Command — copy this
curl -s -I "http://${LAB_HOST:-127.0.0.1}:8080" | grep -iE "(Server|X-Powered-By|Set-Cookie|Content-Security-Policy)"Primary tools to practice this lesson: python3, curl. Reference sites: Output encoding (https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html); Context-specific encoding (https://owasp.org/www-community/attacks/xss/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Encode on exit, validate on entry
Validation rejects bad input; encoding ensures what you display cannot execute. Both layers belong in secure $MY_REPO code — not 'encode instead of validate.'
Defenders CSP and encode; attackers hunt innerHTML misuse — you grep your repo for dangerous sinks.
3. Lab on owned templates only
List three output contexts in $TOY_APP and matching encoder or framework API. Optional: fix one manual concatenation in template.
Ship: context encoding table. Next: XSS Defense.
4. What you ship: context encoding table for $TOY_APP
Three contexts with encoder/API named. Fix one sink in $MY_REPO optional. No live shop XSS. chmod 600.
5. What you record before the next lesson
Date. Context table for $TOY_APP. File t17-m04-l01-context-encoding.txt chmod 600.
6. Wrong vs right: stranger apps vs YOUR repo
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Paste script tags into live shop reviews 'to test encoding.' Use innerHTML with raw user input in $TOY_APP.
Right
Document contexts and encoders on $TOY_APP. Next: XSS Defense.
Mission: context encoding table
1) List HTML, attribute, and URL contexts in $TOY_APP. 2) Name encoder or framework API for each. 3) Optional fix one unsafe sink in $MY_REPO. Never XSS stranger production.
Stuck? Ask Cyberlium AI Mentor
SQL context uses bind parameters — not HTML entity encode.
Knowledge Check
APPLY: Context encoding on Cyberlium applies to:
Multiple choice
Knowledge Check
APPLY: True or False: HTML entity encoding in JS string context is always sufficient.
True or False
Knowledge Check
APPLY: Encode on exit complements:
Multiple choice