Re: [RFC] Improve HTML escape
| From: | Yasuo Ohgaki | Date: | Sun, 02 Feb 2014 03:31:19 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71971@lists.php.net to get a copy of this message | ||
Hi Sara,
On Sun, Feb 2, 2014 at 12:15 PM, Sara Golemon <pollita@php.net> wrote:
> On Sat, Feb 1, 2014 at 7:09 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> > This is a little improvement for HTML escape.
> > https://wiki.php.net/rfc/secure-html-escape
> >
> > "/" escape is recommended by OWASP and we may follow them.
> >
> Could you include some samples of malicious input and what the output
> would actually look like? It's not obvious from the RFC or the link
> referenced.
They don't explain as code. AFAIK This is the case for generating invalid
HTML that destroys HTML tag structure.
<tag attr=<?php htmlentities($str, ENT_QUOTES, 'UTF-8') ?>>
When $str is
sometext /
Produced HTML would be
<tag attr=sometext />
and tag is closed.
The code is broken in first place since attribute must be enclosed by
"(HTML5/XHTML) or '(HTML4), but many (if not most) browsers just allows
attributes without qoutes.
As long as user don't have other mistakes, it's not a security issue. It's
not vulnerable by itself, but it may be possible do some bad thing on some
implementations. It's just a precaution. It's good precaution as it does
not break any existing browsers. IMHO.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net