3 ms·
PSA. Escaping html only helps if you're allowing user-generated text outside of any tag. If you're allowing user-generated text into a html tag (ie. this case.
by dnaquin 17y ago
PSA. Escaping html only helps if you're allowing user-generated text outside of any tag.
If you're allowing user-generated text into a html tag (ie. this case.) Escaping html tags won't help.
- jrockway 17y agoWhy not? The substitution they do is <a href="%s">, and you can "game that" by inserting 'http://foo.com> http://foo.com> other stuff goes here <whatever foo="">' Fine. The literal HTML that the user sees becomes '<a href="http://foo.com>other http://foo.com>other stuff goes here <whatever foo="">'. That's bad. Now if you escape that properly, you get: '<a href="http://foo.com"> http://foo.com"> other stuff goes here <whatever foo="">' Garbage, but not a security problem. (BTW, news.arc fucks up the escaping too, so this example is garbage. Sorry. See nopaste here: http://scsys.co.uk:8001/33063 http://scsys.co.uk:8001/33063 Edit: sigh, that is also broken! Bottom line; none of these things will happen to you if you replace every & with &, every " with ", every ' with ', every < with < and every > with >.)
- dnaquin 17y agoCongratulations, you've just stopped one particular attack. There'll be something you forget. Blacklisting is only a good idea if whitelisting isn't possible. (see the \w above) eg. You forgot. javascript:alert(document.cookie) Which depends on click and in and of itself isn't dangerous but a symptom of a greater problem. edit: except you need to allow more than \w.