note 20125 added to function.strip-tags
| From: | charlieNOSPAM at screaming-penguin dot NS dot com | Date: | Sat, 23 Mar 2002 01:06:07 +0000 |
| Subject: | note 20125 added to function.strip-tags | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-28110@lists.php.net to get a copy of this message | ||
I had issues with the strip_tags() function and all of the examples on this page. Specifically I
wanted to strip potentially malicious HTML tags in input (see CERT CA-2000-02.) All of these
examples AND the strip_tags() function with a list of allowed tags appear to BE VULNERABLE TO CASE.
That means that the applet tag may be disallowed but aPpLeT is not! (Maybe my implemenation had
issues, I dont know, but I was able to subvert all of these examples easily.)
To remedy this I made a function to turn the HTML tags into all upper case (as the example on
preg_replace() page shows) and THEN parse the input replacing malicious tags defined in an array
with a warning. As follows:
function inputCheck($body)
{
$body=preg_replace
("/(<\/?)(\w+)([^>]*>)/e",
"'\\1'.strtoupper('\\2').'\\3'",
$body);
$disallowedTags = array(
"APPLET",
"OBJECT",
"SCRIPT",
"EMBED",
"FORM",
"?",
"%"
);
$count = count($disallowedTags);
foreach ($disallowedTags as $value)
{
$body=str_replace("<".$value, "<b>WARNING:
$value (tag not allowed.) </b> ", $body);
}
return $body;
}
ALSO, whatever method is used, you still need to be careful with attributes, my implementation
intentionally just kills the entire tag if found but does NOT kill nested tags or attributes. As to
when to perform this my recommendation is to do this at INPUT (if using db, files, etc) not at
display as some popular PHP packages do, that way the data is clean, not the presentation, and it is
cleaned up once, not each time it is viewed. That way performance is improved and data can be
re-used, etc.
See this article and phorum thread on screaming-penguin for more info. - http://www.screaming-penguin.com
/main.php?storyid=2255
--
http://www.php.net/manual/en/function.strip-tags.php
http://master.php.net/manage/user-notes.php?action=edit+20125
http://master.php.net/manage/user-notes.php?action=delete+20125
http://master.php.net/manage/user-notes.php?action=reject+20125