note 40674 deleted from function.strip-tags by nlopess
| From: | nlopess@php.net | Date: | Thu, 11 Mar 2004 14:51:42 +0000 |
| Subject: | note 40674 deleted from function.strip-tags by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-66637@lists.php.net to get a copy of this message | ||
Note Submitter: Keiser
----
In reference to the problem of
<tab<table></table>le></tab<table></table>le>, all you have to
do is not allow any html tags, and instead use your own custom ones that are parsed on your own
(such as phpBB's [IMG], etc.). Then in your parser just replace all <'s with <
(ampersand numeral six zero), the html escape code for the less than symbol. This stops all
html/script tags that start with it from working.
Before:
<tab<table></table>le></tab<table></table>le>
After:
<tab<table></table>le></tab<table></table>le>
Now I would really escape the > and many other similar characters that could be used in malicious
ways, but this alone will stop the majority of them. A full list of html escape codes can be found
here:
http://www.december.com/html/spec/codes.html