is it possible to allow a cretain HTML tags in posts
4 posters
Page 1 of 1
is it possible to allow a cretain HTML tags in posts
is it possible to allow a cretain HTML tags in posts
to use some of the HTML tags
and in same way protect forum from the hacking HTML Scripts etc
ts only a question for now
as i being asked few days a go
thanks
to use some of the HTML tags
and in same way protect forum from the hacking HTML Scripts etc
ts only a question for now
as i being asked few days a go
thanks
Michael_vx- Forumember
- Posts : 659
Reputation : 29
Language : Arabic and some English
Location : Egypt
Re: is it possible to allow a cretain HTML tags in posts
odd
thought there should be a reply as the notfication say
thought there should be a reply as the notfication say
Michael_vx- Forumember
- Posts : 659
Reputation : 29
Language : Arabic and some English
Location : Egypt
Re: is it possible to allow a cretain HTML tags in posts
The only way they can "hack" your forum by using CSS, somewhat JS.
This is myway: go ACP > General > Messages and e-mails > Censoring > Word Censoring > Add new word:
If you want to keep <style> tag, then censore the display, all of CSS hack are likely to use display:none.
Edit: dont forget <script
This is myway: go ACP > General > Messages and e-mails > Censoring > Word Censoring > Add new word:
If you want to keep <style> tag, then censore the display, all of CSS hack are likely to use display:none.
- Code:
World: "display:" Replacement: "display;"
- Code:
<div class="ok></div>
<style>.ok {
width: 100000px;
height: 100000px;
position: absolute;
z-index: 99999999;
top: 0;
left: 0;
background: #fff;
}
</style>
- Code:
<div style="width:100000px;height: 100000px;position: absolute;z-index: 99999999;top:0;left:0;background:#fff;"></div>
Edit: dont forget <script
Re: is it possible to allow a cretain HTML tags in posts
@Pamoon the topic starter does not want to censor the tags.
Lost Founder's Password |Forum's Utilities |Report a Forum |General Rules |FAQ |Tricks & Tips
You need one post to send a PM.
You need one post to send a PM.
When your topic has been solved, ensure you mark the topic solved.
Never post your email in public.
Re: is it possible to allow a cretain HTML tags in posts
yes @SLGray, censor the tags is the good way to allow a certain HTML tags in post
for ex: you cant use <span></span> because of censoring
for ex: you cant use <span></span> because of censoring
Re: is it possible to allow a cretain HTML tags in posts
Pamoon wrote:The only way they can "hack" your forum by using CSS, somewhat JS.
This is myway: go ACP > General > Messages and e-mails > Censoring > Word Censoring > Add new word:
If you want to keep <style> tag, then censore the display, all of CSS hack are likely to use display:none.But i recommended you to censore the <style> tag, because if i use this code in the post, your forum still be "hacked" ' -'
- Code:
World: "display:" Replacement: "display;"
But <style> isnt enough, check this lel:
- Code:
<div class="ok></div>
<style>.ok {
width: 100000px;
height: 100000px;
position: absolute;
z-index: 99999999;
top: 0;
left: 0;
background: #fff;
}
</style>So, you need to censore the style= too ' -' (change it to oppagangnamstyle=).
- Code:
<div style="width:100000px;height: 100000px;position: absolute;z-index: 99999999;top:0;left:0;background:#fff;"></div>
Edit: dont forget <script
you mean something like bad words replaceing when i say bad become *** as i want
im not sure but this might not work
let me say the same qeustin with other way
now if i allow HTML in posts
that might allow hackers to hack the forum by some kind of HTML Scripts
i only need few HTML Tags like <div> and </div>
things like that i know it will be safe Tags
Michael_vx- Forumember
- Posts : 659
Reputation : 29
Language : Arabic and some English
Location : Egypt
Re: is it possible to allow a cretain HTML tags in posts
Just filter the word <script> and </script> and make them appear as " ".
And I don't think you need to filter the style tags.
And I don't think you need to filter the style tags.
Re: is it possible to allow a cretain HTML tags in posts
so same might work with iframe
this could do it i guess
if there a better way ill be waiting
if not the topic can be arked as solved
this could do it i guess
if there a better way ill be waiting
if not the topic can be arked as solved
Michael_vx- Forumember
- Posts : 659
Reputation : 29
Language : Arabic and some English
Location : Egypt
Re: is it possible to allow a cretain HTML tags in posts
If you are worried about HTML then just not allow it.
Lost Founder's Password |Forum's Utilities |Report a Forum |General Rules |FAQ |Tricks & Tips
You need one post to send a PM.
You need one post to send a PM.
When your topic has been solved, ensure you mark the topic solved.
Never post your email in public.
Re: is it possible to allow a cretain HTML tags in posts
SLGray wrote:If you are worried about HTML then just not allow it.
dont worry
i gave the warning to the forum owner who asked me about that question
and the other told him about the risks but he still want to use HTML in posts
http://help.ahlamontada.com/t1085280-topic#4920246
this the reason for me to ask here
to see what trick will help to avoid hacking Scripts for him
Michael_vx- Forumember
- Posts : 659
Reputation : 29
Language : Arabic and some English
Location : Egypt
Re: is it possible to allow a cretain HTML tags in posts
what tag is most needed is <div> only
is there something can do the same job in bbcode ?
is there something can do the same job in bbcode ?
Michael_vx- Forumember
- Posts : 659
Reputation : 29
Language : Arabic and some English
Location : Egypt
Re: is it possible to allow a cretain HTML tags in posts
i apologize in the first place
this topic is ready for garbag or archive
i apologize again
this topic is ready for garbag or archive
i apologize again
Michael_vx- Forumember
- Posts : 659
Reputation : 29
Language : Arabic and some English
Location : Egypt
Re: is it possible to allow a cretain HTML tags in posts
Locked as Requested
Lost Founder's Password |Forum's Utilities |Report a Forum |General Rules |FAQ |Tricks & Tips
You need one post to send a PM.
You need one post to send a PM.
When your topic has been solved, ensure you mark the topic solved.
Never post your email in public.
Similar topics
» Can't get tags for topics working using previous help posts
» Bug: HTML tags don't stay in Site name
» Allowing [html] tags to specific usergroups?
» problem with html tags for right and left side.
» Tags that automatically close prematurely in the HTML editor
» Bug: HTML tags don't stay in Site name
» Allowing [html] tags to specific usergroups?
» problem with html tags for right and left side.
» Tags that automatically close prematurely in the HTML editor
Page 1 of 1
Permissions in this forum:
You cannot reply to topics in this forum