note 41304 deleted from function.preg-replace by nlopess

From: Date: Fri, 09 Apr 2004 19:30:31 +0000
Subject: note 41304 deleted from function.preg-replace by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-67918@lists.php.net to get a copy of this message
Note Submitter: pull@hackthissite.org ---- <?php //Code for the function //Anti-XSS Script // (Disallowing possibly harmful scripts) function ptext($ar, $text){ if(!is_array($ar)){ //checks to see if input is array $ar=str_replace("/","\/",$ar); //allows / in user input $num=strlen($ar); //gets length of input $i=0; while($num!=$i){ $val=ord("$ar[$i]"); $art["$i"]='&#'.$val.';'; $arm .=$art[$i]; $i++; } /* The above breaks down the input letter by letter and converts it into an int then changes it to &#NUM; format */ $arg=preg_replace("/$ar/i",$arm,$text); //replaces the text return $arg; //returns formatted text } else{ $x=0; $num2=count($ar); //get number of words in input array while($num2!=$x){ $arf="$ar[$x]"; //for breaking down into &#num; format $nub=$ar[$x]; //for formatting with /$text/i $nub=str_replace("/","\/",$nub); //allowing / in input $arre["$x"]="/$nub/i"; //formatting to /$text/i for preg_replace $num=strlen($arf); //below is the code for breaking //down into &#num; format $i=0; while($num!=$i){ $val=ord("$arf[$i]"); $art["$i"]='&#'.$val.';'; $arm .=$art[$i]; $i++; } $rear["$x"]=$arm; //replacement array $arm=NULL; //resets $arm $x++; } $arg=preg_replace($arre, $rear, $text); //replaces text return $arg; //returns formatted text } } //## EXAMPLE USE ##// $text='God money..... ontext ON On oN load eval java load on eval '; $pn=array("load","on","eval",'cookie', 'document','script','java'); $text=ptext($pn,$text); //this would return God m&#111;&#110;ey..... //&#111;&#110;text &#111;&#110; &#111;&#110; //&#111;&#110; // //&#108;&#111;&#97;&#100; &#101;&#118;&#97;&#108; //&#106;&#97;&#118;&#97; //&#108;&#111;&#97;&#100; &#111;&#110; //&#101;&#118;&#97;&#108; ?> Very usefull for guesbooks, user submitted pages, etc..

« previous php.notes (#67918) next »