4 ms·
It's open source now: https://github.com/ikkez/CryptDown https://github.com/ikkez/CryptDown feel free to add your own ideas and improvements.
by ikkez 11y ago
It's open source now:
https://github.com/ikkez/CryptDown https://github.com/ikkez/CryptDown
feel free to add your own ideas and improvements.
- dsacco 11y agoHey, cool project. As another poster in this thread mentioned, you have a cross-site scripting vulnerability because you don't properly sanitize the decrypted user input. I might work on this if I get a little time later today, but in case I don't, here are a few resources for you: http://stackoverflow.com/questions/3129899/what-are-the-common-defenses-against-xss http://stackoverflow.com/questions/3129899/what-are-the-comm... https://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%29_Prevention_Cheat_Sheet https://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%... The good news is that PHP is so widespread that there are really great tutorials and libraries for sanitizing user input and preventing cross-site scripting. Good luck!
- ikkez 11y agoshould be fixed now.
- nialo 11y agoIs there a written description of the protocol used between the client and server anywhere?