Hack Attempt Prevention with strip_tags()

From: Date: Wed, 18 Jul 2001 15:15:38 +0000
Subject: Hack Attempt Prevention with strip_tags()
Groups: php.general 
Request: Send a blank email to php-general+get-58449@lists.php.net to get a copy of this message
I've been reading on php.net about the strip_tags function, and it seems that many people have been writing their own function. Is this because a malicious user could put something like <b onmouseover="for(i=0;i<100;i++) window.open('www.somesite.com');">Long message...</b> or would strip_tags prevent this? What do you think of strip_tags() vs writing your own function?

« previous php.general (#58449) next »