Maugrim The Reaper's Blog

Pádraic Brady on PHP, PHP Game Development and More

License

Creative Commons License - Some Rights Reserved
Original content in this work is licensed under a Creative Commons License

Powered by

Serendipity PHP Weblog

Syndicate This Blog

Statistics

Last entry: 2010-08-09 22:00
414 entries written
1581 comments have been made

Archives

2010

September 0 entries
August 1 entries
July 1 entries
June 2 entries
May 5 entries
April 0 entries
March 0 entries
February 1 entries
January 0 entries

2009

December 0 entries
November 0 entries
October 2 entries
September 6 entries
August 2 entries
July 4 entries
June 5 entries
May 0 entries
April 1 entries
March 6 entries
February 6 entries
January 10 entries

2008

December 3 entries
November 4 entries
October 0 entries
September 0 entries
August 0 entries
July 0 entries
June 0 entries
May 4 entries
April 8 entries
March 2 entries
February 6 entries
January 8 entries

2007

December 7 entries
November 9 entries
October 3 entries
September 6 entries
August 0 entries
July 7 entries
June 6 entries
May 5 entries
April 6 entries
March 5 entries
February 9 entries
January 6 entries

2006

December 5 entries
November 14 entries
October 6 entries
September 6 entries
August 1 entries
July 5 entries
June 16 entries
May 12 entries
April 10 entries
March 19 entries
February 29 entries
January 20 entries

2005

December 4 entries
November 17 entries
October 15 entries
September 8 entries
August 1 entries
July 0 entries
June 6 entries
May 25 entries
April 7 entries
March 9 entries
February 6 entries
January 1 entries

2004

December 0 entries
November 5 entries
October 1 entries
September 1 entries
August 0 entries
July 3 entries
June 1 entries
May 11 entries

Calendar

Back September '10
Mon Tue Wed Thu Fri Sat Sun
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30      

Quicksearch

Comments

Richard about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Mon, 30.08.2010 23:22
This is quite an interesting p ost and also informational. Ce rtainly one of such posts that brings a fresh perspect [...]


Bobby about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 17.08.2010 22:24
I just wanted to thank you for the article and the research. I was looking for a solution and was surprised to fin [...]


Tyson Sturdivant about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Mon, 16.08.2010 19:30
Does anyone have any input on "Universal Feed Parser" and it s effectiveness?


Pádraic Brady about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Mon, 16.08.2010 17:44
Is it a big table? ;-) Don't wo rry about it - I'm completely harmless.


Miha about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Thu, 12.08.2010 15:59
OMG. What did I write. You men tioned html5lib in your post. And I go on mentioning just th at. /me is now ashamed [...]


Miha about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Wed, 11.08.2010 20:46
html5lib (http://code.google.c om/p/html5lib/) is the one I r un on a few days ago, so I'm p robably guessing that th [...]


Padraic Brady about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Wed, 11.08.2010 19:56
I haven't decided on it yet. A t the moment, many server side development tools are in the same boat. libxml2 and t [...]


Miha about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Wed, 11.08.2010 19:32
@Padraic: What will you do in a 6months when html5 becomes p opular and along with it stand ardized parser. Its prob [...]


Maarten about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Wed, 11.08.2010 12:45
looking forward to your soluti on. To be honest, we're using HTMLPurifier and I have yet to encounter big problems [...]


Padraic Brady about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 18:44
Quoting from the original repo rt (26 June '10): "Bonus vu lnerability from a brief look through of the blacklist [...]


Jeremy Cook about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 18:30
Thanks for the excellent artic le. Very informative.


Brett Bieber about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 17:43
I believe you're incorrect reg arding the -ms-behavior css er ror in HTML_Safe. The blacklis t includes "behavior" wh [...]


Pádraic Brady about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 11:18
Yes, it's being proposed to Ze nd Framework. HTMLPurifier rea lly is that good, largely beca use it properly normalis [...]


Pádraic Brady about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 11:13
Hi Santosh, As the article notes, CSS may be used to styl e elements in such a way that may overlay or expand th [...]


Peter about HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 10:15
So if HTML Purifier is that go od, will you still be proposin g your own for inclusion into Zend?


Top Referrers