http://pturing.livejournal.com/ ([identity profile] pturing.livejournal.com) wrote in [personal profile] maradydd 2005-02-19 07:18 am (UTC)

Re: just one question....

yup, I even have my own system for dealing with cross-site scripting :)
When tags are allowed, I pass everything through html tidy first, and then filter for the naughty stuff. I have tested it against all known XSS methods, but I may still have some work to do on it since I'm using a blacklist filter, rather than the recommended method of using a whitelist. Using tidy of course has the added benefit that my pages are still valid xhtml, even when users put in invalid html.

pulled off deep evil by taking advantage..
yes, I think I remember a post to that effect

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org