Re: [RFC] Improve HTML escape

From: Date: Sun, 02 Feb 2014 03:31:19 +0000
Subject: Re: [RFC] Improve HTML escape
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-71971@lists.php.net to get a copy of this message
Hi Sara, On Sun, Feb 2, 2014 at 12:15 PM, Sara Golemon <pollita@php.net> wrote: > On Sat, Feb 1, 2014 at 7:09 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > > This is a little improvement for HTML escape. > > https://wiki.php.net/rfc/secure-html-escape > > > > "/" escape is recommended by OWASP and we may follow them. > > > Could you include some samples of malicious input and what the output > would actually look like? It's not obvious from the RFC or the link > referenced. They don't explain as code. AFAIK This is the case for generating invalid HTML that destroys HTML tag structure. <tag attr=<?php htmlentities($str, ENT_QUOTES, 'UTF-8') ?>> When $str is sometext / Produced HTML would be <tag attr=sometext /> and tag is closed. The code is broken in first place since attribute must be enclosed by "(HTML5/XHTML) or '(HTML4), but many (if not most) browsers just allows attributes without qoutes. As long as user don't have other mistakes, it's not a security issue. It's not vulnerable by itself, but it may be possible do some bad thing on some implementations. It's just a precaution. It's good precaution as it does not break any existing browsers. IMHO. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#71971) next »