note 33993 deleted from function.strip-tags by nlopess
| From: | nlopess@php.net | Date: | Thu, 11 Mar 2004 14:55:08 +0000 |
| Subject: | note 33993 deleted from function.strip-tags by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-66651@lists.php.net to get a copy of this message | ||
Note Submitter: gavin@vess.com
----
Judging from the sheer number of "holes" found in the posted samples, clearly, creating
"safe" html is a difficult task.
Consider an alternative (html to text) from Tom:
http://www.perl.com/CPAN/authors/Tom_Christiansen/scripts/striphtml.gz
FYI, I noticed that no one has yet reported a flaw in inputCheck() from charlieNOSPAM's. It
missed the case:
<img src="http://.com/transparent.gif"
width=300 height=300 onmouseover="alert('hello')"
By dropping the trailing '>', the tag isn't uppercased, and then fails to match
the rule (supposing that "IMG" was added to the list of tags to disable).
Most badhtml2safehtml() functions seem to miss the possibility of mixed case in the tags name,
dangerous attributes, or malformed HTML that still executes something dangerous in a forgiving web
browser.