|
|||||||||||
|
Preventing XSS
From: Ulf Harnhammar <metaur(at)operamail.com>
Date: Fri Jun 20 2003 - 11:54:17 EDT
I see that a lot of people here are interested in preventing Cross-Site Scripting. Why don't you join the people who are working on filters for it (like my kses in PHP, or someone else's HTML::StripScripts::Parser in Perl), so we end up with really robust open-source implementations that we can point people to? echo "<a href=\"$url\">Homepage</a>\n"; you can cause an XSS problem if $url is: http://www.somestupidsite.tk/" onMouseOver="alert(57) Just processing "<" and ">" won't help you. In this type of fragment, quotes and apostrophes must be handled as well. // Ulf Harnhammar
kses - PHP HTML filter
-- ____________________________________________ http://www.operamail.com Get OperaMail Premium today - USD 29.99/year Powered by OutblazeReceived on Fri Jun 20 13:23:10 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:53 EDT |
||||||||||
|
|||||||||||