The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Why is letting HTML dangerous?
I have read everywhere that letting a user post pure HTML is a site suicide.
I have accepted it for years as an axiom, like 1+1=2. However, I've seen popular blogging sites to allow their bloggers to change the template by providing them its whole HTML, including <script> tags and everything! Aren't they afraid? Have they taken any "special measures" to prevent abuse, and if so, what measures? |
#2
|
||||
|
||||
Yes, allowing HTML can let hackers inject malicious Javascript into a page, which could potentially steal people's cookie data.
|
#3
|
|||
|
|||
Can you provide an example???
|
#4
|
||||
|
||||
Quote:
|
#5
|
||||
|
||||
No, because then you'd go around trying to exploit forums...
|
#6
|
|||
|
|||
Quote:
If so, then these blogging sites are not doing anything dangerous, each blog is its blogger's responsibility... |
#7
|
||||
|
||||
But your forum is your responsibility.
|
#8
|
|||
|
|||
Definately.
But I'm going to add blogs to it, and I'm wondering if I should let them customize the whole html template or just the css. That's why I asked |
#9
|
|||
|
|||
There's also things like that Myspace friends worm that happened early on over there.
Had some shit where there was some javascript embedded on someone's profile and then everyone who came to that page was added as a friend to that person AND it also copied itself to the viewing person's profile. Within a day or so the guy who started it was friends with everyone on Myspace. Something like that. People can do weird, potentially dangerous things when they can stick whatever javascript they want on a page. |
#10
|
|||
|
|||
So I'd better let them customize just the css?
Are there any exploits that someone can perform from css? (We suppose that the code will strip html tags so that's not the case) |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|