NYCPHP Meetup

NYPHP.org

sanitizing user-submitted html

Chris Snyder chris at psydeshow.org
Fri May 30 15:17:26 EDT 2003


I've whipped up a pcom-to-be that will render user-submitted HTML safe 
from all of the cross-site-scripting attacks that I'm aware of.
If you think you know any clever tricks for getting javascript or nasty 
tags (like <embed>) around text filters, could you please have a go at 
breaking it?
http://chxo.com/scripts/safe_html-test.php

Thanks!

    chris.




More information about the talk mailing list