Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #31219

Re: Javascript injection

Newsgroups comp.lang.javascript
Subject Re: Javascript injection
From "Evertjan." <exxjxw.hannivoort@inter.nl.net>
References <2a5cf91a-151b-4379-9510-5dcd5a5bb196@googlegroups.com> <fof8sbd9g2sg3ll5lf232fkd4oapjdvrth@4ax.com> <XnsA673AEAA339D3eejj99@194.109.6.166> <nq4n62$hjg$1@dont-email.me>
Date 2016-08-31 10:25 +0200
Message-ID <XnsA67569FA9267Feejj99@194.109.6.166> (permalink)

Show all headers | View raw


Aleksandro <aleksandro@gmx.com> wrote on 30 Aug 2016 in 
comp.lang.javascript:

> On 29/08/16 12:10, Evertjan. wrote:
>> Hans-Georg Michna <hans-georgNoEmailPlease@michna.com> wrote on 29 Aug
>> 2016 in comp.lang.javascript: 
>> 
>>> On Sun, 28 Aug 2016 22:58:08 -0700 (PDT),
>>> bit-naughty@hotmail.com wrote:
>>>
>>>> If I have a "forum" type of site, where stuff is being posted, and
>>>> stored in the backend (in a MySQL database, using PHP), say,....can
>>>> anyone type in Javascript into the post to accomplish naughty things?
>>>> What's the most nefarious thing anyone can do? All I can think of is
>>>> that someone would deface the page somehow, that *that* post is on,
>>>> which, really, I can't see the point of..... Anything else? ...and how
>>>> do I protect against it? (the post will probably be displayed inside a
>>>> DIV on the page, I think....) 
>>>
>>> I would not even allow ordinary users to enter HTML tags, i.e.
>>> have them filtered out. This, of course, includes <script ...>
>>> tags, so users cannot inject any script.
>> 
>> theText = theText.replace(/</g,'&lt;');
> 
> Serversidely OT: http://php.net/str_replace

You better [for this NG] use ASP + Jscript, making my suggestion ON topic.



-- 
Evertjan.
The Netherlands.
(Please change the x'es to dots in my emailaddress)

Back to comp.lang.javascript | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Javascript injection bit-naughty@hotmail.com - 2016-08-28 22:58 -0700
  Re: Javascript injection "Christoph M. Becker" <cmbecker69@arcor.de> - 2016-08-29 11:27 +0200
  Re: Javascript injection Hans-Georg Michna <hans-georgNoEmailPlease@michna.com> - 2016-08-29 15:58 +0200
    Re: Javascript injection "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2016-08-29 17:10 +0200
      Re: Javascript injection Aleksandro <aleksandro@gmx.com> - 2016-08-30 16:35 -0300
        Re: Javascript injection "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2016-08-31 10:25 +0200
          Re: Javascript injection "Christoph M. Becker" <cmbecker69@arcor.de> - 2016-08-31 12:43 +0200

csiph-web