Re: malicious code removal
| From: | Daniel Convissor | Date: | Fri, 21 Jul 2000 19:42:30 +0000 |
| Subject: | Re: malicious code removal | ||
| References: | 1 2 3 4 5 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-7620@lists.php.net to get a copy of this message | ||
Hi Again David:
David VanHorn wrote:
>
> I need to display a block of user entered text.
> Is there a function or routine to remove html and java from a text variable?
# The following characters are allowed in URL's:
# !#$%&'()*+,-./09:;=?@AZ_az~
# (where "09", "AZ" and "az" represent ranges)
# (according to RFC 2396, http://www.rfc-editor.org/rfc/rfc2396.txt)
# (sorted by ISO 8859-1 (Latin-1) character code number)
$Out = substr( ereg_replace("[^!#-9:;=?-Z_a-z~]", "", $In), 0, $Max );
Of course, adjust to suit your purposes.
More important question: does anyone have opinions on whether this approach
can be tripped up by some combination of special characters causing something
to either get through or cause an error in the code?
Thanks,
--
T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y
More than just answers. Solutions. (SM)
http://www.analysisandsolutions.com/
4015 7 Av #4, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409