Re: RFC: Implementing a core anti-XSS escaping class

From: Date: Wed, 19 Sep 2012 18:41:15 +0000
Subject: Re: RFC: Implementing a core anti-XSS escaping class
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-63173@lists.php.net to get a copy of this message
Hi Steve, The CSS escaping strategy would escape all non-alphanumerics to CSS hex sequences ;). As a result, HTML escaping is not strictly necessary. Paddy On Wed, Sep 19, 2012 at 7:08 PM, Steve Clay <steve@mrclay.org> wrote: > On 9/19/12 1:48 PM, Pádraic Brady wrote: >> >> <style> >> body { >> background-color: <? echo $e->escapeCss('white'); ?> >> } >> </style> > > > Hmmm, the following is a valid value: > > "</style><script>alert('xss')" > > ...for both the content and font-family CSS properties. Gotta love HTML! > > What would escapeCss do with them? Do we need to wrap in escapeHtml? > > Steve > -- > http://www.mrclay.org/ > > > -- > PHP Internals - PHP Runtime Development Mailing List > To unsubscribe, visit: http://www.php.net/unsub.php > -- Pádraic Brady http://blog.astrumfutura.com http://www.survivethedeepend.com Zend Framework Community Review Team

« previous php.internals (#63173) next »