Friday, September 12, 2008

PHP htmlentities Function

Whenever you allow your users to submit text to your website, you need to be careful that you don't leave any security holes open for malicious users to exploit. If you are ever going to allow user submitted text to be visible by the public you should consider using the htmlentities function to prevent them from running html code and scripts that may be harmful to your visitors.

HP - Converting HTML into Entities

The htmlentities function takes a string and returns the same string with HTML converted into HTML entities. For example, the string

"'";

//Lets make it safer before we use it
$userInputEntities = htmlentities($userInput);

//Now we can display it
echo $userInputEntities;

The HTML output of the above script would be as follows:
Safe Raw HTML Code:

I am going to hax0r your site, hahaha!
< script type='text/javascript' >
window.location = 'http://www.example.com/'
< /script >'

If we had not used htmlentities to convert any HTML code into safe entities, this is what the raw HTML code would be and it would have redirect a visitor to example.com.

Dangerous Raw HTML Code:

I am going to hax0r your site, hahaha!
'

Those two HTML code examples are what you would see if you were to view source on the web page. However, if you were just viewing the output normally in your browser you would see the following.

Safe Display:
I am going to hax0r your site, hahaha! '

Dangerous Display:
You'd see whatever spammer site that the malicious user had sent you to. Probably some herbal supplement site or weight loss pills would be displayed.

When Would You Use htmlentities?
Anytime you allow users to submit content to your website, that other visitors can see, you should consider removing the ability to let them use HTML. Although this will remove a lot of cool things that your users can do, like making heavily customized content, it will prevent your site from a lot of common attacks. With some custom coding you can just remove specific tags from running, but that is beyond the scope of this lesson.

Just remember, that when allowing users to submit content to your site you are also giving them access to your website. Be sure you take the proper precautions.

No comments: