Hack Attempt Prevention with strip_tags()
| From: | david jarvis | Date: | Wed, 18 Jul 2001 15:15:38 +0000 |
| Subject: | Hack Attempt Prevention with strip_tags() | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-58449@lists.php.net to get a copy of this message | ||
I've been reading on php.net about the strip_tags function, and it seems that many people have
been writing their own function. Is this because a malicious user could put something like <b
onmouseover="for(i=0;i<100;i++) window.open('www.somesite.com');">Long
message...</b> or would strip_tags prevent this?
What do you think of strip_tags() vs writing your own function?