Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Antigen forwarded attachment

From: <Antigen_MISS(at)securityfocus.com>
Date: Fri Jun 20 2003 - 04:06:52 EDT


The entire message "RE: Preventing cross site scripting", originally sent to you by Mutallip Ablimit (mutax@insi.co.jp), has been forwarded to you from the Antigen Quarantine area. This message may have been re-scanned by Antigen and handled according to the appropriate scan job's settings.

<<Entire Message.eml>>

attached mail follows:


Yes, replace all of the unacceptable tags with "", it will work fine. And for a plus,
PHP has a strip_tags() function.
Didn't have tried yet, but I think it could be used to remove all unacceptable tags.
In this case, may be you have to make a list of all allowed tags.

strip_tags($Text, "<allowed tag>");

This will only allows the "<allowed tag>".

Regards,



Mutellip Ablimit
INSI
mutax@insi.co.jp
Do you need help?X

-----Original Message-----
From: David Cameron [mailto:dcameron@itis-now.com] Sent: Friday, June 20, 2003 10:51 AM
To: Andrew Beverley; webappsec@securityfocus.com Subject: RE: Preventing cross site scripting

Create a list of unacceptable tags in an array (eg applet, embed), loop through the array and generate a regexpr based on the array, something of the form:
<(applet)|(embed).?> and replace all instances with "".

Do the same for any possible closing tags ie: </(applet)|(embed)> and replace all instances with "".

BTW the RegExpr may be wrong, I'm not all that hot on RegExprs, but you get the idea.

regards
David Cameron
nOw.b2b
dcameron@itis-now.com

> -----Original Message-----

>
>

> I am currently writing a web application that, as a small part of it,
>

> I would like to know the best way of filtering out undesirable html. I
>

> However, there is a lot of tags that are acceptable. Another approach
>

> Are there any functions available (for php) that will take a html page
>

> Thanks,
>

> Andrew Beverley
>
>
>
>
>
Received on Fri Jun 20 08:43:04 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:53 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library