note 80197 added to function.eregi
| From: | mbfreightatthegmailplace at osu1 dot php dot net | Date: | Thu, 03 Jan 2008 22:53:40 +0000 |
| Subject: | note 80197 added to function.eregi | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-134733@lists.php.net to get a copy of this message | ||
keran at kiwi-interactive dot com wrote (5ish years ago) 07-Mar-2003 08:21
$feedback = "Error: $email isn't a valid mail address!";
return $feedback;
-- and --
$feedback = "Error: $domain isn't a valid domain!";
return $feedback;
I've been crushed with patching up XSS and anytime you get user input, it's best to just
not show it back to them if possible. The auditor loves throwing these at me:
>"><script>alert(123)</script><" in the url, in forms, everywhere.
Some looking around and you can find and build an amazing testing string.
I have found that using htmlentities($user_input) isn't enough, either. There are a few tricks
that can help like
// from http://us3.php.net/manual/en/function.strip-tags.php
while($input != strip_tags($input)) {
$input = strip_tags($input);
}
In my case, I'm starting off by testing for <[tag]> as well as keyword() and then do some
preg_replace ing.
----
Server IP: 64.71.164.2
Probable Submitter: 70.166.14.174
----
Manual Page -- http://www.php.net/manual/en/function.eregi.php
Edit -- https://master.php.net/note/edit/80197
Del: integrated -- https://master.php.net/note/delete/80197/integrated
Del: useless -- https://master.php.net/note/delete/80197/useless
Del: bad code -- https://master.php.net/note/delete/80197/bad+code
Del: spam -- https://master.php.net/note/delete/80197/spam
Del: non-english -- https://master.php.net/note/delete/80197/non-english
Del: in docs -- https://master.php.net/note/delete/80197/in+docs
Del: other reasons-- https://master.php.net/note/delete/80197
Reject -- https://master.php.net/note/reject/80197
Search -- https://master.php.net/manage/user-notes.php