Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #4184

Re: BB type posting - is this secure?

From Curtis Dyer <dyer85@gmail.com>
Newsgroups comp.lang.php
Subject Re: BB type posting - is this secure?
Date 2011-12-29 23:29 +0000
Organization A noiseless patient Spider
Message-ID <jdit4j$jj1$1@dont-email.me> (permalink)
References <ptqpf75jh2fra5qfu8jhum3bn4ug6r17ot@4ax.com>

Show all headers | View raw


Michael Joel <no@please.com> wrote:

> I am allowing posts to the page and wanted to see if this is
> secure. 
> 
> data from sql is placed in an array (say $MyArray):
> 
> $MyArray["Post"] = nl2br(stripslashes($MyArray["Post"]));
> 
> $MyArray["Post"] = strip_tags($MyArray["Post"], "<BR>");

Alternatively, you might call nl2br() last.

> I notice with this text like <script>alert("hi");</script> is
> rendered as literal so no script is actually recognised.
> 
> So is this gooed enough or is there something else I need to do?
> 
> Mike

After calling strip_tags(), you'll want to call htmlspecialchars() 
to ensure ensure remaining HTML characters are escaped.

-- 
Curtis Dyer
<?$x='<?$x=%c%s%c;printf($x,39,$x,39);?>';printf($x,39,$x,39);?>

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 17:45 -0500
  Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 00:14 +0100
  Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2011-12-29 23:29 +0000
    Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 23:27 -0500
      Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 00:29 -0500
        Re: BB type posting - is this secure? Jerry Stuckle <jstucklex@attglobal.net> - 2011-12-30 05:59 -0500
  Re: BB type posting - is this secure? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-12-30 10:59 +0100
    Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 10:01 -0500
      Re: BB type posting - is this secure? Michael Fesser <netizen@gmx.de> - 2011-12-30 19:14 +0100
      Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 21:39 +0100
        Re: BB type posting - is this secure? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-01 19:20 +0100
      Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2012-01-04 07:24 +0000

csiph-web