Re: HREF exploit
| From: | Matthew Kendall | Date: | Thu, 27 Jul 2000 23:07:41 +0000 |
| Subject: | Re: HREF exploit | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-8690@lists.php.net to get a copy of this message | ||
"David Norman" <norny@geocities.com> wrote...
> ...I'd like to allow HREF tags...
Instead of trying to allow anchor tags and then having to parse them to
filter undesirable content, why not disallow all tags from the submission
then parse it and construct anchor tags whereever you see a likely link;
anything that starts http:// or www. This is what SourceForge does in forum
postings for example.
You could use strip_tags() to get rid of all HTML, then use a simple regex
to find http://foo.com and replace it with <a
href="http://foo.com">http://foo.com</a>