Re: [RFC] Improve HTML escape
| From: | Yasuo Ohgaki | Date: | Mon, 03 Feb 2014 22:21:45 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72147@lists.php.net to get a copy of this message | ||
Hi Stas,
On Tue, Feb 4, 2014 at 7:14 AM, Stas Malyshev <smalyshev@sugarcrm.com>wrote:
> > Some users has to confirm standard like PCI DSS.
> > PCI DSS requires to follow security standards and guidelines from OWASP,
> > SANS, etc.
> >
> > Why not make PHP standard compliant?
> > It does not hart existing applications at all and this is simple enough
> > change.
>
> I'm sorry, could you please quote me a standard that requires PHP to
> escape / in function called htmlentites?
I've already written the URL to OWASP.
PCI DSS v3 states in section 6.5
Develop applications based on secure coding guidelines.
Note: The vulnerabilities listed at 6.5.1 through 6.5.10 were current with
industry best
practices when this version of PCI DSS was published. However, as industry
best
practices for vulnerability management are updated (for example, the OWASP
Guide,
SANS CWE Top 25, CERT Secure Coding, etc.), the current best practices must
be used
for these requirements.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net