Maugrim The Reaper's Blog
Entries from March 2009
License
Original content in this work is licensed under a
Creative Commons License
Powered by
Syndicate This Blog
RSS 2.0 feed
ATOM 1.0 feed
Planet PHP
My interview at dot KDE - Henri Bergius
Thursday, September 2. 2010
Zend Framework is a BOSSie Award Winner - Zend Developer Zone
Wednesday, September 1. 2010
Speaking at PHPNW 2010 - John Mertic
Wednesday, September 1. 2010
Contributing to ZendFramework - ThinkPHP /dev/blog - PHP
Wednesday, September 1. 2010
Big step forward in Modular Database Applications with DataObjects - Alan Knowles
Tuesday, August 31. 2010
The fine art of application virtualization - John Lim (PHP Everywhere - By John Lim)
Tuesday, August 31. 2010
Collecting Garbage: PHP's take on variables - Derick Rethans
Tuesday, August 31. 2010
How to Roll Your Own JavaScript Compressor with PHP and the Closure Compiler - SitePoint » PHP
Tuesday, August 31. 2010
Beware of the default Apache 2 config for PHP - Ilia Alshanetsky
Monday, August 30. 2010
PHP Manager for IIS 7 – beta release - Ruslan Yakushev
Monday, August 30. 2010
Statistics
Last entry:
2010-08-09 22:00
414
entries written
1581
comments have been made
Topics from March, 2009
396 -
Zend Framework: Survive The Deep End Update
Sunday, March 22. 2009. Posted by
Pádraic Brady
in
PHP General
Zend Framework
395 -
The Case For Dependency Injection - Part 2
Friday, March 13. 2009. Posted by
Pádraic Brady
in
PHP General
PHP Security
394 -
The Case For Dependency Injection - Part 1
Thursday, March 12. 2009. Posted by
Pádraic Brady
in
PHP General
PHP Security
Zend Framework
393 -
Can't see the forest for the trees? Quit micro-optimising and try again.
Tuesday, March 10. 2009. Posted by
Pádraic Brady
in
PHP General
PHP Security
392 -
The Mockery: An Independent Mock Object and Stub Framework for PHP5
Friday, March 6. 2009. Posted by
Pádraic Brady
in
PHP General
PHP Security
Zend Framework
391 -
Cowen Is My Shepherd...
Thursday, March 5. 2009. Posted by
Pádraic Brady
in
Irishisms
View as PDF:
This month
|
Full blog
Calendar
March '09
Mon
Tue
Wed
Thu
Fri
Sat
Sun
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Quicksearch
Comments
Richard
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Mon, 30.08.2010 23:22
This is quite an interesting p ost and also informational. Ce rtainly one of such posts that brings a fresh perspect [...]
Bobby
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 17.08.2010 22:24
I just wanted to thank you for the article and the research. I was looking for a solution and was surprised to fin [...]
Tyson Sturdivant
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Mon, 16.08.2010 19:30
Does anyone have any input on "Universal Feed Parser" and it s effectiveness?
Pádraic Brady
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Mon, 16.08.2010 17:44
Is it a big table?
Don't wo rry about it - I'm completely harmless.
Miha
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Thu, 12.08.2010 15:59
OMG. What did I write. You men tioned html5lib in your post. And I go on mentioning just th at. /me is now ashamed [...]
Miha
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Wed, 11.08.2010 20:46
html5lib (http://code.google.c om/p/html5lib/) is the one I r un on a few days ago, so I'm p robably guessing that th [...]
Padraic Brady
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Wed, 11.08.2010 19:56
I haven't decided on it yet. A t the moment, many server side development tools are in the same boat. libxml2 and t [...]
Miha
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Wed, 11.08.2010 19:32
@Padraic: What will you do in a 6months when html5 becomes p opular and along with it stand ardized parser. Its prob [...]
Maarten
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Wed, 11.08.2010 12:45
looking forward to your soluti on. To be honest, we're using HTMLPurifier and I have yet to encounter big problems [...]
Padraic Brady
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 18:44
Quoting from the original repo rt (26 June '10): "Bonus vu lnerability from a brief look through of the blacklist [...]
Jeremy Cook
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 18:30
Thanks for the excellent artic le. Very informative.
Brett Bieber
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 17:43
I believe you're incorrect reg arding the -ms-behavior css er ror in HTML_Safe. The blacklis t includes "behavior" wh [...]
Pádraic Brady
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 11:18
Yes, it's being proposed to Ze nd Framework. HTMLPurifier rea lly is that good, largely beca use it properly normalis [...]
Pádraic Brady
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 11:13
Hi Santosh, As the article notes, CSS may be used to styl e elements in such a way that may overlay or expand th [...]
Peter
about
HTML Sanitisation: The Devil's In The Details (And The Vulnerabilities)
Tue, 10.08.2010 10:15
So if HTML Purifier is that go od, will you still be proposin g your own for inclusion into Zend?
Categories
AJAX
Irishisms (48)
PC Gaming (6)
PHP Game Development (27)
Astrum Futura (6)
Quantum Star SE (11)
The Merchant
PHP General (170)
Openid and Yadis (13)
Zend Framework (79)
PHP Security (128)
All categories
Archives
September 2010
August 2010
July 2010
Recent...
Older...
Top Referrers
Show tagged entries
application security
article
astrum futura
asynchronous processing
atom
bdd
behavior-driven development
behaviour-driven development
benchmark
book
deep end
dependency injection
design patterns
devnetwork
docbook
documentation
eve online
games
htmlpurifier
inversion of control
irish php user group
irishisms
maugrim
microformat
mock objects
mockery
model
mutateme
mutation testing
mvc
oauth
openid
openid and yadis
pc gaming
pear
phing
php
php game development
php games
php general
php security
phpmock
phpspec
phpunit
poka-yoke
qgl
quantum game library
quantum star se
rantings
rss
simpletest
snarl
solar empire
surviving the deep end
symfony
tdd
test spy
tutorial
unit testing
xp programming
xrd
xrds
xss
yadis
yaml
zend framework
zf proposal
zfstde