Dirty List – White List
In software testing, the terms Dirty List and White List are used to describe two contrasting approaches to managing inputs, user actions, or system elements during testing. They are typically employed in the context of access control, input validation, and test case design.
Dirty List
The Dirty List (sometimes called a “blacklist”) is a collection of disallowed, invalid, or malicious inputs, actions, or elements that the system must explicitly reject. The goal of the Dirty List is to test the system’s ability to identify and handle potentially harmful or unacceptable inputs effectively.
- Purpose: To ensure the system is robust against known threats or misuse scenarios.
- Examples:
- A list of forbidden file extensions (e.g.,
.exe,.bat) to prevent unauthorized uploads. - Disallowed SQL keywords (e.g.,
DROP,DELETE) to test SQL injection vulnerabilities. - A set of invalid email formats to check the system’s input validation.
- A list of forbidden file extensions (e.g.,
- Testing Focus:
- Security testing: Preventing attacks like SQL injection, XSS (Cross-Site Scripting), and directory traversal.
- Negative testing: Ensuring the system fails gracefully when encountering invalid inputs.
White List
The White List is a predefined collection of allowed, valid, or acceptable inputs, actions, or elements that the system should explicitly accept. The White List enforces strict validation by rejecting anything that is not explicitly permitted.
- Purpose: To define a safe boundary for acceptable system interactions and minimize the risk of unintended behavior.
- Examples:
- Allowed file extensions for uploads (e.g.,
.jpg,.png,.pdf). - Approved domains for email addresses (e.g.,
@example.com). - Permitted characters for input fields (e.g., alphanumeric only).
- Allowed file extensions for uploads (e.g.,
- Testing Focus:
- Functional testing: Verifying that valid inputs are correctly accepted and processed.
- Security testing: Preventing attacks by allowing only predefined safe inputs.
- Compliance testing: Ensuring the system adheres to regulatory or business standards.
In practice, software testing often combines both strategies for comprehensive coverage. For example, a system may implement a White List to define acceptable file uploads while simultaneously using a Dirty List to block known malicious patterns. Automated testing tools like Selenium or Cypress can simulate scenarios involving both lists, validating the system’s response to both allowed and disallowed inputs.





