note 80197 deleted from function.eregi by cmb

From: Date: Sun, 20 Oct 2019 08:40:30 +0000
Subject: note 80197 deleted from function.eregi by cmb
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-212676@lists.php.net to get a copy of this message
Note Submitter: mbfreight atthe gmail place ---- keran at kiwi-interactive dot com wrote (5ish years ago) 07-Mar-2003 08:21 $feedback = "Error: $email isn't a valid mail address!"; return $feedback; -- and -- $feedback = "Error: $domain isn't a valid domain!"; return $feedback; I've been crushed with patching up XSS and anytime you get user input, it's best to just not show it back to them if possible. The auditor loves throwing these at me: >"><script>alert(123)</script><" in the url, in forms, everywhere. Some looking around and you can find and build an amazing testing string. I have found that using htmlentities($user_input) isn't enough, either. There are a few tricks that can help like // from http://us3.php.net/manual/en/function.strip-tags.php while($input != strip_tags($input)) { $input = strip_tags($input); } In my case, I'm starting off by testing for <[tag]> as well as keyword() and then do some preg_replace ing.

« previous php.notes (#212676) next »