Re: HREF exploit

From: Date: Wed, 26 Jul 2000 21:46:37 +0000
Subject: Re: HREF exploit
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-8416@lists.php.net to get a copy of this message
Not to burst your bubble or anything, but it is pretty much impossible to allow people to enter HTML on your page in any sort of secure manner. Even a <p> tag can be used maliciously by embedding JavaScript in it that ends up redirecting users elsewhere, or worse. -Rasmus On Wed, 26 Jul 2000, David Norman wrote: > There's an exploit in the message system of some PHP code I'm developing > that's really annoying. > > <a href=" >link</a> > > Note: there's only one quotation mark in the tag. It causes the whole page > not to display in Netscape. I've included the sum of my work. I've tried to > pluck out the stuff that's in the middle of the tag, count the number of > quotes, and just delete all quotes if it counts an odd number (since the tag > will work the same) and leave them in if even because they'll all cancel > each other out. > > What I've got now doesn't work right because it grabs *everything* between > the very first carrot and the very last carrot. Can anyone think of a loop > to wrap around what I've got to grab the correct stuff between carrots? > Heck, I don't care if it's totally different code... just as long as it > works. > >

« previous php.general (#8416) next »