Re: HREF exploit
| From: | Rasmus Lerdorf | Date: | Wed, 26 Jul 2000 21:46:37 +0000 |
| Subject: | Re: HREF exploit | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-8416@lists.php.net to get a copy of this message | ||
Not to burst your bubble or anything, but it is pretty much impossible to
allow people to enter HTML on your page in any sort of secure
manner. Even a <p> tag can be used maliciously by embedding JavaScript in
it that ends up redirecting users elsewhere, or worse.
-Rasmus
On Wed, 26 Jul 2000, David Norman wrote:
> There's an exploit in the message system of some PHP code I'm developing
> that's really annoying.
>
> <a href=" >link</a>
>
> Note: there's only one quotation mark in the tag. It causes the whole page
> not to display in Netscape. I've included the sum of my work. I've tried to
> pluck out the stuff that's in the middle of the tag, count the number of
> quotes, and just delete all quotes if it counts an odd number (since the tag
> will work the same) and leave them in if even because they'll all cancel
> each other out.
>
> What I've got now doesn't work right because it grabs *everything* between
> the very first carrot and the very last carrot. Can anyone think of a loop
> to wrap around what I've got to grab the correct stuff between carrots?
> Heck, I don't care if it's totally different code... just as long as it
> works.
>
>