Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #4183
| Path | csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!gegeweb.org!de-l.enfer-du-nord.net!feeder1.enfer-du-nord.net!newsfeed.CARNet.hr!gregory.BNet.hr!not-for-mail |
|---|---|
| From | "A" <a@a.a> |
| Newsgroups | comp.lang.php |
| Subject | Re: BB type posting - is this secure? |
| Date | Fri, 30 Dec 2011 00:14:34 +0100 |
| Organization | B.net Hrvatska d.o.o. |
| Lines | 24 |
| Message-ID | <jdis94$3m5$1@gregory.bnet.hr> (permalink) |
| References | <ptqpf75jh2fra5qfu8jhum3bn4ug6r17ot@4ax.com> |
| NNTP-Posting-Host | dh207-32-117.xnet.hr |
| X-Trace | gregory.bnet.hr 1325200484 3781 88.207.32.117 (29 Dec 2011 23:14:44 GMT) |
| X-Complaints-To | abuse@globalnet.hr |
| NNTP-Posting-Date | Thu, 29 Dec 2011 23:14:44 +0000 (UTC) |
| X-Priority | 3 |
| X-MSMail-Priority | Normal |
| X-Newsreader | Microsoft Outlook Express 6.00.2900.5931 |
| X-RFC2646 | Format=Flowed; Original |
| X-MimeOLE | Produced By Microsoft MimeOLE V6.00.2900.6157 |
| Xref | x330-a1.tempe.blueboxinc.net comp.lang.php:4183 |
Show key headers only | View raw
"Michael Joel" <no@please.com> wrote in message
news:ptqpf75jh2fra5qfu8jhum3bn4ug6r17ot@4ax.com...
>I am allowing posts to the page and wanted to see if this is secure.
> data from sql is placed in an array (say $MyArray):
> $MyArray["Post"] = nl2br(stripslashes($MyArray["Post"]));
> $MyArray["Post"] = strip_tags($MyArray["Post"], "<BR>");
> I notice with this text like <script>alert("hi");</script> is rendered
> as literal so no script is actually recognised.
strip_tags($MyArray["Post"], "<BR>");
doesn't really help because it removes only <BR> tags and not other HTML
tags.
Use htmlspecialchars - it renders all HTML special characters to safe
variants for displaying.
And before inserting them into database use parametrized query to stop all
sql injection.
http://stackoverflow.com/questions/1299182/prepared-parameterized-query-with-pdo
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 17:45 -0500
Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 00:14 +0100
Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2011-12-29 23:29 +0000
Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 23:27 -0500
Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 00:29 -0500
Re: BB type posting - is this secure? Jerry Stuckle <jstucklex@attglobal.net> - 2011-12-30 05:59 -0500
Re: BB type posting - is this secure? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-12-30 10:59 +0100
Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 10:01 -0500
Re: BB type posting - is this secure? Michael Fesser <netizen@gmx.de> - 2011-12-30 19:14 +0100
Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 21:39 +0100
Re: BB type posting - is this secure? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-01 19:20 +0100
Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2012-01-04 07:24 +0000
csiph-web