Re: RFC: Implementing a core anti-XSS escaping class
| From: | Pádraic Brady | Date: | Wed, 19 Sep 2012 18:41:15 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63173@lists.php.net to get a copy of this message | ||
Hi Steve,
The CSS escaping strategy would escape all non-alphanumerics to CSS
hex sequences ;). As a result, HTML escaping is not strictly
necessary.
Paddy
On Wed, Sep 19, 2012 at 7:08 PM, Steve Clay <steve@mrclay.org> wrote:
> On 9/19/12 1:48 PM, Pádraic Brady wrote:
>>
>> <style>
>> body {
>> background-color: <? echo $e->escapeCss('white'); ?>
>> }
>> </style>
>
>
> Hmmm, the following is a valid value:
>
> "</style><script>alert('xss')"
>
> ...for both the content and font-family CSS properties. Gotta love HTML!
>
> What would escapeCss do with them? Do we need to wrap in escapeHtml?
>
> Steve
> --
> http://www.mrclay.org/
>
>
> --
> PHP Internals - PHP Runtime Development Mailing List
> To unsubscribe, visit: http://www.php.net/unsub.php
>
--
Pádraic Brady
http://blog.astrumfutura.com
http://www.survivethedeepend.com
Zend Framework Community Review Team