You are here: Re: Question About Regular Expression « PHP Programming Language « IT news, forums, messages
Re: Question About Regular Expression

Posted by Michael Fesser on 10/23/07 20:11

..oO(joey.powell@topscene.com)

>I have a web app with two textboxes. The first textbox allows users to
>type in various text, html tags and CSS. The second textbox, on post
>back, will display/markup the text entered from the first textbox. The
>idea is that users can insert their own "descriptions" for items
>maintained by the website. Obviously if I am going to do something
>like this I should be careful, with the threat of XSS attacks, etc...

Instead of allowing them to use full HTML, you should consider to use
something like BBCode for example. Give them just the things they need,
not more.

With full HTML there are _many_ different ways to include scripting.
It's very hard to block them all, so you shouldn't allow it at all.

Micha

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация