Re: RFC: Implementing a core anti-XSS escaping class
| From: | Rasmus Lerdorf | Date: | Tue, 18 Sep 2012 19:50:08 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63112@lists.php.net to get a copy of this message | ||
On 09/18/2012 03:46 PM, Pádraic Brady wrote:
> Bear in mind the RFC, in userland (and likely any PECL ext) implements
> the ESAPI rules. They've been hacked on a lot over the years which is
> why I made sure they were followed exactly. It's very unlikely that a
> browser bug could scupper these unless they allowed in more unencoded
> characters to be taken advantage of. There are benefits to reusing
> pre-peer review rules.
Sure, but you have potential for buffer overflows, regex
backtrack/recursion issues and general programming errors when this
moves to C. I guarantee there will be dozens of bugs in the first
version no matter who writes it.
-Rasmus