May 23, 2006

If you use a blacklist to remove JavaScript and miss one your site is vulnerable. If you use htmlentities and forget one, you are not vulnerable; the worst-case scenario is that doesn’t convert to bold. ... The Regex coach. to try regular expressions; it simplifies the process. ... (3-7 characters long) or we specifically allow the ... ................
................