note 26221 deleted from function.strip-tags by vrana
| From: | vrana@php.net | Date: | Mon, 22 Dec 2003 16:18:05 +0000 |
| Subject: | note 26221 deleted from function.strip-tags by vrana | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-62330@lists.php.net to get a copy of this message | ||
Note Submitter: interdist SPAM_IS_EVIL @myrealbox.com
----
I'd like to note, that the code which removes SCRIPT tags with everything in them, as suggested
by [mrmaxxx333 at triad dot rr dot com] and corrected then by [tim at e-matters dot de],
doesn't work in the case when between the opening tag and the closing one a '<' is
found. The whole block remains unchanged.
To get around this, I changed the regex to the following:
preg_replace('/<(script|style)[^>]*>.+<\/(script|style)[^>]*>/is',
'', $cleaned_up_text);
This one worked for me perfectly (it strips also STYLE blocks, if found). An additional interesting
functionality of this regex, which I discovered, is that even overlapping blocks are being cleaned
up, i.e. if you have
One*<script language="blah">some malicious code; some more code; <style
type="text/css">some html to try and confuse our regex</script> p { font-weight:
bold; } </style dummy_flag>*Two
after preg_replace'ing it, you'll remain with the string "One**Two" only.