Re: [PHP] Re: security in guest book and user forums

2003-01-05 Thread Justin French
on 05/01/03 11:54 PM, Jurre Thiel ([EMAIL PROTECTED]) wrote: > The bad side of this that all other HTML tags than and will be > removed. So add some more tags!! Gz! Which would you prefer? Pretty colours and bold text, or a page full of unclosed tags, evil javascripts, and other harmfull

Re: [PHP] Re: security in guest book and user forums

2003-01-05 Thread Jurre Thiel
The bad side of this that all other HTML tags than and will be removed. > on 05/01/03 5:24 AM, Seraphim ([EMAIL PROTECTED]) wrote: > > > I use the htmlspecialchars() function to disable all html. This function > > basically puts a '\' in front of eacht html character and thus disables all > > ht

Re: [PHP] Re: security in guest book and user forums

2003-01-04 Thread Justin French
on 05/01/03 5:24 AM, Seraphim ([EMAIL PROTECTED]) wrote: > I use the htmlspecialchars() function to disable all html. This function > basically puts a '\' in front of eacht html character and thus disables all > html. > You may not want to do this if you want to allow, for example or > other frie

[PHP] Re: security in guest book and user forums

2003-01-04 Thread Tularis
most forums do this Seraphim wrote: Anders Thoresson wrote: I've seen both guest books and user forums "hacked" by users who enter javascript or other code, and that way redirects vistors to other sites or do other unwelcome things. What expressions should I look for and not allow in my forms

[PHP] Re: security in guest book and user forums

2003-01-04 Thread Seraphim
Anders Thoresson wrote: > I've seen both guest books and user forums "hacked" by users who > enter javascript or other code, and that way redirects vistors to > other sites or do other unwelcome things. What expressions should I > look for and not allow in my forms? I use the htmlspecialchars()