Re: HREF exploit

From: Date: Fri, 28 Jul 2000 04:44:21 +0000
Subject: Re: HREF exploit
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-8709@lists.php.net to get a copy of this message
Heya: Matthew Kendall wrote: > > You could use strip_tags() to get rid of all HTML, then use a simple regex > to find http://foo.com and replace it with <a > href="http://foo.com">http://foo.com</a> There's an article on http://www.phpbuilder.com/ about a method to allow users to markup their code w/o using html, then when it's about to be viewed by someone, the PHP class runs it through some regular expressions that turn it into html. Interesting, --Dan -- T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y More than just answers. Solutions. (SM) http://www.analysisandsolutions.com/ 4015 7 Av #4, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409

« previous php.general (#8709) next »