4 ms·
I may be naive, but how about this? a) Escape everything 100%. b) Look for <a> tags, grab their href attribute, escape it, and insert them as <a href='$1'>$2<
by jeff18 16y ago
I may be naive, but how about this?
a) Escape everything 100%.
b) Look for <a> tags, grab their href attribute, escape it, and insert them as <a href='$1'>$2</a>.
c) Do the same for <b>, <p>, etc.
How would that be vulnerable to XSS? A small whitelist of HTML would be replaced safely, and any script tags and so on would be escaped and displayed as is.
- joeyh 16y agoIn your example above, $1 may contain javascript. The easy way is href="data:text/javascript", or even href="javascript:alert('foo')"", but there are probably a dozen other ways, including data:image/svg. There's no real way to "escape" url attributes (some browsers are known to run 'any: ex' as javascript); parsing the url seems to be the only approach that works.
- axod 16y agoSo only allow http:// http:// and https:// https:// in URLs?
- deleted 16y ago[deleted]