Re: Removing security-problematic chars from strings
| From: | John W. Holmes | Date: | Fri, 21 Nov 2003 13:38:18 +0000 |
| Subject: | Re: Removing security-problematic chars from strings | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-170558@lists.php.net to get a copy of this message | ||
Wouter van Vliet wrote:
John W. HolmesYou could do this if you want to allow cross site scripting vulerabilities on your site: Hello <b onmouseover="alert('hi');">you</b>. And prevent such evil text as "<grin>" or "<foo>"... -- ---John Holmes... Amazon Wishlist: www.amazon.com/o/registry/3BEXC84AB3A5E/ php|architect: The Magazine for PHP Professionals – www.phparch.comTroy S wrote:If you're worried about HTML code being entered (guess from desire to strip <, > and /) and messing up your site's layout, you might wanna call strip_tags($String, $AllowedTags); where $AllowedTags is a string like '<b><u><i>' if you want to allow bold, underline and italics.What is the best way to remove the characters from strings that may cause security problems? Namely, `, ', ", <, >, \ and all non-printing strings. Did I miss any? Thanks.Why do you need to remove them? So I can't type <grin>? Is that a security violation? All you need to do is use htmlentities() and/or addslashes() to protect data being displayed or entered into a database.