note 80197 deleted from function.eregi by cmb
| From: | cmb@php.net | Date: | Sun, 20 Oct 2019 08:40:30 +0000 |
| Subject: | note 80197 deleted from function.eregi by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-212676@lists.php.net to get a copy of this message | ||
Note Submitter: mbfreight atthe gmail place
----
keran at kiwi-interactive dot com wrote (5ish years ago) 07-Mar-2003 08:21
$feedback = "Error: $email isn't a valid mail address!";
return $feedback;
-- and --
$feedback = "Error: $domain isn't a valid domain!";
return $feedback;
I've been crushed with patching up XSS and anytime you get user input, it's best to just
not show it back to them if possible. The auditor loves throwing these at me:
>"><script>alert(123)</script><" in the url, in forms, everywhere.
Some looking around and you can find and build an amazing testing string.
I have found that using htmlentities($user_input) isn't enough, either. There are a few tricks
that can help like
// from http://us3.php.net/manual/en/function.strip-tags.php
while($input != strip_tags($input)) {
$input = strip_tags($input);
}
In my case, I'm starting off by testing for <[tag]> as well as keyword() and then do some
preg_replace ing.