note 80197 added to function.eregi

From: Date: Thu, 03 Jan 2008 22:53:40 +0000
Subject: note 80197 added to function.eregi
Groups: php.notes 
Request: Send a blank email to php-notes+get-134733@lists.php.net to get a copy of this message
keran at kiwi-interactive dot com wrote (5ish years ago) 07-Mar-2003 08:21 $feedback = "Error: $email isn't a valid mail address!"; return $feedback; -- and -- $feedback = "Error: $domain isn't a valid domain!"; return $feedback; I've been crushed with patching up XSS and anytime you get user input, it's best to just not show it back to them if possible. The auditor loves throwing these at me: >"><script>alert(123)</script><" in the url, in forms, everywhere. Some looking around and you can find and build an amazing testing string. I have found that using htmlentities($user_input) isn't enough, either. There are a few tricks that can help like // from http://us3.php.net/manual/en/function.strip-tags.php while($input != strip_tags($input)) { $input = strip_tags($input); } In my case, I'm starting off by testing for <[tag]> as well as keyword() and then do some preg_replace ing. ---- Server IP: 64.71.164.2 Probable Submitter: 70.166.14.174 ---- Manual Page -- http://www.php.net/manual/en/function.eregi.php Edit -- https://master.php.net/note/edit/80197 Del: integrated -- https://master.php.net/note/delete/80197/integrated Del: useless -- https://master.php.net/note/delete/80197/useless Del: bad code -- https://master.php.net/note/delete/80197/bad+code Del: spam -- https://master.php.net/note/delete/80197/spam Del: non-english -- https://master.php.net/note/delete/80197/non-english Del: in docs -- https://master.php.net/note/delete/80197/in+docs Del: other reasons-- https://master.php.net/note/delete/80197 Reject -- https://master.php.net/note/reject/80197 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#134733) next »