Re: HREF exploit
| From: | Daniel Convissor | Date: | Fri, 28 Jul 2000 04:44:21 +0000 |
| Subject: | Re: HREF exploit | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-8709@lists.php.net to get a copy of this message | ||
Heya:
Matthew Kendall wrote:
>
> You could use strip_tags() to get rid of all HTML, then use a simple regex
> to find http://foo.com and replace it with <a
> href="http://foo.com">http://foo.com</a>
There's an article on http://www.phpbuilder.com/ about
a method to allow
users to markup their code w/o using html, then when it's about to be viewed
by someone, the PHP class runs it through some regular expressions that turn
it into html.
Interesting,
--Dan
--
T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y
More than just answers. Solutions. (SM)
http://www.analysisandsolutions.com/
4015 7 Av #4, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409