note 20125 deleted from function.strip-tags by vrana

From: Date: Mon, 22 Dec 2003 16:08:36 +0000
Subject: note 20125 deleted from function.strip-tags by vrana
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-62323@lists.php.net to get a copy of this message
Note Submitter: charlieNOSPAM@screaming-penguin.NS.com ---- I had issues with the strip_tags() function and all of the examples on this page. Specifically I wanted to strip potentially malicious HTML tags in input (see CERT CA-2000-02.) All of these examples AND the strip_tags() function with a list of allowed tags appear to BE VULNERABLE TO CASE. That means that the applet tag may be disallowed but aPpLeT is not! (Maybe my implemenation had issues, I dont know, but I was able to subvert all of these examples easily.) To remedy this I made a function to turn the HTML tags into all upper case (as the example on preg_replace() page shows) and THEN parse the input replacing malicious tags defined in an array with a warning. As follows: function inputCheck($body) { $body=preg_replace ("/(<\/?)(\w+)([^>]*>)/e", "'\\1'.strtoupper('\\2').'\\3'", $body); $disallowedTags = array( "APPLET", "OBJECT", "SCRIPT", "EMBED", "FORM", "?", "%" ); $count = count($disallowedTags); foreach ($disallowedTags as $value) { $body=str_replace("<".$value, "<b>WARNING: $value (tag not allowed.) </b> ", $body); } return $body; } ALSO, whatever method is used, you still need to be careful with attributes, my implementation intentionally just kills the entire tag if found but does NOT kill nested tags or attributes. As to when to perform this my recommendation is to do this at INPUT (if using db, files, etc) not at display as some popular PHP packages do, that way the data is clean, not the presentation, and it is cleaned up once, not each time it is viewed. That way performance is improved and data can be re-used, etc. See this article and phorum thread on screaming-penguin for more info. - http://www.screaming-penguin.com /main.php?storyid=2255

« previous php.notes (#62323) next »