1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Question / Suggestion

Discussion in 'Forum Information, Questions and Feedback' started by Aurora, Apr 4, 2009.

?

Yes or No?

  1. Yes

    90.0%
  2. No

    10.0%
Thread Status:
Not open for further replies.

Question / Suggestion

  1. BirdofPrey

    BirdofPrey New Member

    Joined:
    Aug 20, 2007
    Messages:
    4,985
    Likes received:
    5
    Trophy points:
    0
    From:
    Arizona
    how are [tr] and [td] a security risk?
    Also why in the hell would it substitute HTML tags in the first place?
     
  2. MeisterX

    MeisterX Hyperion

    Joined:
    Jul 23, 2007
    Messages:
    4,949
    Likes received:
    17
    Trophy points:
    38
    From:
    New Port Richey, FL
    Because there is a difference between putting text into a pre-designed HTML plugin box and putting code between two html tags.

    Large difference.
     
  3. BirdofPrey

    BirdofPrey New Member

    Joined:
    Aug 20, 2007
    Messages:
    4,985
    Likes received:
    5
    Trophy points:
    0
    From:
    Arizona
    What? That doesn't annswer either question.

    Anyways, I know HTML, and there are only a couple of tags that can cause security problem, and those are linking tabs, the security risk comes from directing you to another site. Table tags only control presentation, they can't cause security problems.

    Putting CODE between the tags is different as well, thats CODE, has nothing to do with HTML at all, and to my knowledge, putting scripts in the posts won't acually run them.
     
  4. LordKerwyn

    LordKerwyn New Member

    Joined:
    Jul 28, 2007
    Messages:
    2,259
    Likes received:
    9
    Trophy points:
    0
    From:
    Deep Space
    BoP what kind of damage do you think would happen to the layout if I made a post that simply said "</tr>" and it was with HTML active?
     
  5. MeisterX

    MeisterX Hyperion

    Joined:
    Jul 23, 2007
    Messages:
    4,949
    Likes received:
    17
    Trophy points:
    38
    From:
    New Port Richey, FL
    Incorrect. Anything that can save text within an HTML code can access the server.

    I'm not going to discuss this with you.

    There are more dangers than <script> and <iframe>. For instance, a user could make a never-ending page with a simple css script.
     
    Last edited: Apr 6, 2009
  6. Aurora

    Aurora The Defiant

    Joined:
    Sep 12, 2007
    Messages:
    3,732
    Likes received:
    15
    Trophy points:
    38
    From:
    The Netherlands
    Well, at least my quistion got awnsered. Thanks Jon. Looking forward to seeing this implemented. The forum will be even better without those nasty advertisers.

    Locked.
     
Thread Status:
Not open for further replies.