Anti XSS Filter PHP

Page 2 of 2 FirstFirst 12
Results 16 to 24 of 24
  1. #16
    Live Ocottish Sverlord Joopie is offline
    LegendRank
    Jun 2010 Join Date
    The NetherlandsLocation
    2,773Posts

    Re: Anti XSS Filter PHP

    What about strip_tags/htmlentries/real escape string

    We don't need that hardcore function of you?

    Also, Where is that post of kryptos, I wanna like it ;x

    Edit: forgot filter_var...

  2. #17
    I don't even know azaidi is offline
    MemberRank
    Apr 2010 Join Date
    the NetherlandsLocation
    2,065Posts

    Re: Anti XSS Filter PHP

    Quote Originally Posted by pepijndut View Post
    Owh okay.. What is XSS :P
    I don't know anything about security xD

    Pepijn =D
    Javascript exploits like putting <script>alert('You suck')</script> in your motto in the client and then go to the Online Users page and look at your motto. If it isn't filtered it would give you an alert "You suck".

  3. #18
    Account Upgraded | Title Enabled! nickymonsma is offline
    MemberRank
    Sep 2009 Join Date
    The NetherlandsLocation
    232Posts

    Re: Anti XSS Filter PHP

    True :p;PPPPPPP:P

  4. #19
    [̲̅$̲̅(̲̅1̲̅)̲̅$ ̲̅] leenster is offline
    MemberRank
    May 2008 Join Date
    KanaadaLocation
    992Posts
    Quote Originally Posted by azaidi View Post
    Javascript exploits like putting <script>alert('You suck')</script> in your motto in the client and then go to the Online Users page and look at your motto. If it isn't filtered it would give you an alert "You suck".
    You can also do that with room descriptions if your cms shows your rooms.
    Posted via Mobile Device

  5. #20
    I am Nobody. pepijndut is offline
    MemberRank
    Oct 2009 Join Date
    328Posts

    Re: Anti XSS Filter PHP

    Thanks everyone =D. I now know what XSS is :P

    Pepijn =D

  6. #21
    I don't even know azaidi is offline
    MemberRank
    Apr 2010 Join Date
    the NetherlandsLocation
    2,065Posts

    Re: Anti XSS Filter PHP

    Quote Originally Posted by leenster View Post
    You can also do that with room descriptions if your cms shows your rooms.
    Posted via Mobile Device
    There are some more things but the motto exploit is the most important one.

  7. #22
    Account Upgraded | Title Enabled! Pure is offline
    MemberRank
    May 2008 Join Date
    809Posts

    Re: Anti XSS Filter PHP

    i hurd u no like indents or whitespace

  8. #23
    IT-Developer djboetz is offline
    MemberRank
    Aug 2010 Join Date
    SwedenLocation
    210Posts

    Re: Anti XSS Filter PHP

    XSS may refer to:
    Cross-site scripting, a vulnerability in web applications which attackers may exploit to steal users' information
    XSS file, a Microsoft Visual Studio Dataset Designer Surface Data file
    Assan language, has the ISO 639-3 code xss

  9. #24
    1 + 3 + 3 = 7 EvilCoder is offline
    MemberRank
    Jul 2009 Join Date
    /home/mvdworpLocation
    334Posts

    Re: Anti XSS Filter PHP

    This is real crap.

    You practicly stole this injection filter from web, and its so useless.

    Code:
    foreach($_GET as $key => $value){
      $_GET[$key] = mysql_real_escape_string(htmlspecialchars(addslashes($value),ENT_QUOTES));
    }
    foreach($_POST as $key => $value){
      $_POST[$key] = mysql_real_escape_string(htmlspecialchars(addslashes($value),ENT_QUOTES));
    }
    foreach($_REQUEST as $key => $value){
      $_REQUEST[$key] = mysql_real_escape_string(htmlspecialchars(addslashes($value),ENT_QUOTES));
    }
    Past this in your config.php file. And you're done. That is all useless crap.

    Quote Originally Posted by joopie View Post
    What about strip_tags/htmlentries/real escape string

    We don't need that hardcore function of you?

    Also, Where is that post of kryptos, I wanna like it ;x

    Edit: forgot filter_var...
    Agree. He is just reposting functions with some function.

    WTH?! Nothing is even calling the function: function RemoveXSS($val).....
    You're really dumb with PHP. You need to call the function if you add it.

    omg?!?!. This guy thinks php does all the work itself >_<'



Page 2 of 2 FirstFirst 12

Advertisement