note 40674 deleted from function.strip-tags by nlopess

From: Date: Thu, 11 Mar 2004 14:51:42 +0000
Subject: note 40674 deleted from function.strip-tags by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-66637@lists.php.net to get a copy of this message
Note Submitter: Keiser ---- In reference to the problem of <tab<table></table>le></tab<table></table>le>, all you have to do is not allow any html tags, and instead use your own custom ones that are parsed on your own (such as phpBB's [IMG], etc.). Then in your parser just replace all <'s with &#60 (ampersand numeral six zero), the html escape code for the less than symbol. This stops all html/script tags that start with it from working. Before: <tab<table></table>le></tab<table></table>le> After: &#60tab&#60table>&#60/table>le>&#60/tab&#60table>&#60/table>le> Now I would really escape the > and many other similar characters that could be used in malicious ways, but this alone will stop the majority of them. A full list of html escape codes can be found here: http://www.december.com/html/spec/codes.html

« previous php.notes (#66637) next »