note 33993 deleted from function.strip-tags by nlopess

From: Date: Thu, 11 Mar 2004 14:55:08 +0000
Subject: note 33993 deleted from function.strip-tags by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-66651@lists.php.net to get a copy of this message
Note Submitter: gavin@vess.com ---- Judging from the sheer number of "holes" found in the posted samples, clearly, creating "safe" html is a difficult task. Consider an alternative (html to text) from Tom: http://www.perl.com/CPAN/authors/Tom_Christiansen/scripts/striphtml.gz FYI, I noticed that no one has yet reported a flaw in inputCheck() from charlieNOSPAM's. It missed the case: <img src="http://.com/transparent.gif" width=300 height=300 onmouseover="alert('hello')" By dropping the trailing '>', the tag isn't uppercased, and then fails to match the rule (supposing that "IMG" was added to the list of tags to disable). Most badhtml2safehtml() functions seem to miss the possibility of mixed case in the tags name, dangerous attributes, or malformed HTML that still executes something dangerous in a forgiving web browser.

« previous php.notes (#66651) next »