<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: SafeHTML - cleaning form input</title>
	<atom:link href="http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/</link>
	<description>News, opinion, and fresh thinking for web developers and designers. The official podcast of sitepoint.com.</description>
	<pubDate>Tue, 02 Dec 2008 00:55:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: psojiakmht</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-161389</link>
		<dc:creator>psojiakmht</dc:creator>
		<pubDate>Tue, 23 Jan 2007 17:47:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-161389</guid>
		<description>&lt;a href="http://agybicdwq.com" rel="nofollow"&gt;rvlbjrkf&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://agybicdwq.com" rel="nofollow">rvlbjrkf</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: SitePoint Blogs &#187; Tim&#8217;s comment challenge&#8230;</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-25237</link>
		<dc:creator>SitePoint Blogs &#187; Tim&#8217;s comment challenge&#8230;</dc:creator>
		<pubDate>Mon, 22 May 2006 15:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-25237</guid>
		<description>[...] For comment markup, what to we want to point Tim at? As mentioned before, SafeHTML (packaged under PEAR as HTML_Safe) would allow posting raw HTML, perhaps with help from tidy to make sure it&#8217;s XHTML. There is PHP Markdown (don&#8217;t know much about this e.g. security record / UTF-8 handling) for a fairly standard markup. Alternatively Dokuwiki&#8217;s parser could be extracted (with a little hacking)&#8212;shouldn&#8217;t harm UTF-8 and shouldn&#8217;t result is broken XHTML. What else? [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] For comment markup, what to we want to point Tim at? As mentioned before, SafeHTML (packaged under PEAR as HTML_Safe) would allow posting raw HTML, perhaps with help from tidy to make sure it&#8217;s XHTML. There is PHP Markdown (don&#8217;t know much about this e.g. security record / UTF-8 handling) for a fairly standard markup. Alternatively Dokuwiki&#8217;s parser could be extracted (with a little hacking)&#8212;shouldn&#8217;t harm UTF-8 and shouldn&#8217;t result is broken XHTML. What else? [&#8230;]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: mwmitchell</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-14400</link>
		<dc:creator>mwmitchell</dc:creator>
		<pubDate>Fri, 24 Feb 2006 03:09:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-14400</guid>
		<description>Whipped up a little template class based on your idea Harry, of using short tags with htmlentities: http://www.sitepoint.com/forums/showpost.php?p=2529188&#38;postcount=53

- matt</description>
		<content:encoded><![CDATA[<p>Whipped up a little template class based on your idea Harry, of using short tags with htmlentities: <a href="http://www.sitepoint.com/forums/showpost.php?p=2529188&amp;postcount=53" rel="nofollow">http://www.sitepoint.com/forums/showpost.php?p=2529188&amp;postcount=53</a></p>
<p>- matt</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Roman Ivanov</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-14227</link>
		<dc:creator>Roman Ivanov</dc:creator>
		<pubDate>Tue, 21 Feb 2006 07:57:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-14227</guid>
		<description>Helgi Þormar: HTML_Safe is most recent version, such as SafeHTML.

I update both packages simultaneously.</description>
		<content:encoded><![CDATA[<p>Helgi Þormar: HTML_Safe is most recent version, such as SafeHTML.</p>
<p>I update both packages simultaneously.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Sandbox B3ta &#187; Cleaning up the Input</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-14216</link>
		<dc:creator>Sandbox B3ta &#187; Cleaning up the Input</dc:creator>
		<pubDate>Tue, 21 Feb 2006 03:45:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-14216</guid>
		<description>[...] Harry Fuecks blogs about cleaning up form input which is something I need to look into. One of the comments points to PHP Input Filter which looks like it does things the simple way, i.e. I may be able to use it . . .   February 21st 2006 Posted to Code [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Harry Fuecks blogs about cleaning up form input which is something I need to look into. One of the comments points to PHP Input Filter which looks like it does things the simple way, i.e. I may be able to use it . . .   February 21st 2006 Posted to Code [&#8230;]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: worchyld</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-14187</link>
		<dc:creator>worchyld</dc:creator>
		<pubDate>Mon, 20 Feb 2006 17:44:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-14187</guid>
		<description>What about Input Filter on http://cyberai.com/inputfilter/</description>
		<content:encoded><![CDATA[<p>What about Input Filter on <a href="http://cyberai.com/inputfilter/" rel="nofollow">http://cyberai.com/inputfilter/</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: HarryF</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-14134</link>
		<dc:creator>HarryF</dc:creator>
		<pubDate>Sun, 19 Feb 2006 15:25:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-14134</guid>
		<description>KSES I had heard of - never looked at it too deeply but, from, seems to be a serious attempt.

OK - when I get some time will do a comparison.</description>
		<content:encoded><![CDATA[<p>KSES I had heard of - never looked at it too deeply but, from, seems to be a serious attempt.</p>
<p>OK - when I get some time will do a comparison.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Mullenweg</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-14121</link>
		<dc:creator>Matt Mullenweg</dc:creator>
		<pubDate>Sat, 18 Feb 2006 22:44:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-14121</guid>
		<description>How does this compare to something like KSES?

http://sourceforge.net/projects/kses</description>
		<content:encoded><![CDATA[<p>How does this compare to something like KSES?</p>
<p><a href="http://sourceforge.net/projects/kses" rel="nofollow">http://sourceforge.net/projects/kses</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: HarryF</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-14120</link>
		<dc:creator>HarryF</dc:creator>
		<pubDate>Sat, 18 Feb 2006 21:35:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-14120</guid>
		<description>I guess this needs link to as well: http://blog.bitflux.ch/wiki/XSS_Prevention</description>
		<content:encoded><![CDATA[<p>I guess this needs link to as well: <a href="http://blog.bitflux.ch/wiki/XSS_Prevention" rel="nofollow">http://blog.bitflux.ch/wiki/XSS_Prevention</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: HarryF</title>
		<link>http://www.sitepoint.com/blogs/2006/02/17/safehtml-cleaning-form-input/#comment-14119</link>
		<dc:creator>HarryF</dc:creator>
		<pubDate>Sat, 18 Feb 2006 21:33:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1425#comment-14119</guid>
		<description>&lt;blockquote&gt;
safeHTML should pass all the XSS examples on http://ha.ckers.org/xss.html
&lt;/blockquote&gt;

Playing around with the demo, looks OK. Thanks for the link - that really needs turning into some unit tests, to run against these sort of projects.

&lt;blockquote&gt;
http://hvge.sk/scripts/tagwall/ Not documented, but really worth a try. Works really good on some websites I know.
&lt;/blockquote&gt;

Like the first impressions there - nice code. Not sure it's doing quite the same thing though - seems more focused on stripping particular HTML tags rather than XSS prevention. Will look further.</description>
		<content:encoded><![CDATA[<blockquote><p>
safeHTML should pass all the XSS examples on <a href="http://ha.ckers.org/xss.html" rel="nofollow">http://ha.ckers.org/xss.html</a>
</p></blockquote>
<p>Playing around with the demo, looks OK. Thanks for the link - that really needs turning into some unit tests, to run against these sort of projects.</p>
<blockquote><p>
<a href="http://hvge.sk/scripts/tagwall/" rel="nofollow">http://hvge.sk/scripts/tagwall/</a> Not documented, but really worth a try. Works really good on some websites I know.
</p></blockquote>
<p>Like the first impressions there - nice code. Not sure it&#8217;s doing quite the same thing though - seems more focused on stripping particular HTML tags rather than XSS prevention. Will look further.</p>]]></content:encoded>
	</item>
</channel>
</rss>
