![]() |
Why is HTML in forums so dangerous?
In the forum manager // Allow HTML // Admin Help it says
Quote:
I know you can use vbcode and that's fine, and you can make new code to cover tags such as <strike>. It's just sometimes a <table> with css would be really useful in a post. |
Quote:
Javascript is probably the biggest concern, but there many other annoyances. |
Quote:
There are times when I enable HTML - Site staff access to post only - trusted usergroup w/ users (people that need it on for whatever reason) - moderated post/thread rights on the forum if open to every day members Quote:
Custom BB Codes - vBulletin Manual Its syntax is similar to HTML, but it has the benefit that you (the administrator) can define exactly what codes are allowable in order to prevent unwanted formatting or malicious use. |
Quote:
Hi, you mention trusted usergroup would or could this include users I've "created" to post RSS feeds. they are in a unique group which isn't viewable on groups and isn't joinable. I've just noticed some of the yahoo alerts post html links which may be pictures of whatever, but just looks a mess. I don't want to moderate every post. As the users are made up by me is it safe to allow them to use html, I mean nobody can hijack their usename right? or wrong? I've been hacked, as has others with similar forum topics - and that person is still around and determined to take us all down, so its quite important that I keep things as secure as poss - but I like this rss thingy and want it to post correctly. In relation to this, I assume on VBoptions I have to allow html - and assume I then go to usergroup permissions to disallow it for all groups except my RSS feeders? I know basic html only and am a master at the find this code, above that, add this code type instructions I get here.. but that is the extent of my knowledge, so please forgive me if I've just asked a bunch of stupid questions. TIA |
Here is what I usaly do when I need HTML enabled on a forum, and have all people from a usergroup have access in posting.
Find the forum that you made and edit the usergroups and turn off all options in "Post / Thread Permissions" for the usergroups you want to stop from posting. Everyone you move to the custom usergroup can post in that HTML enabled forum with out problems. |
Or, if you didnt want to restrict posting for everyone, don't turn on HTML at the Forum Level, use my Mod: https://vborg.vbsupport.ru/showthread.php?t=96926
|
^_^ - kall nice !! :D
|
Quote:
To save me doing two posts, Thanks also to Zachariah :) |
Also, if you're an XHTML/CSS validation freak, then you'd be allowing users to potentially ruin your markup. Not a security issue, and it wouldn't even necessarily break the site, but if you care about such things, then it matters.
I've considered a form of forum sponsorship which allows vendors in my industry to have their own forum, with HTML enabled, to post newsletters. I've mixed feelings about it. |
Heh, I made a special hack for forcing signatures with HTML to be approved by a moderator and then I look through them all and change the XHTML to be valid. I'm a markup nazi.
|
All times are GMT. The time now is 06:51 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|