<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: HTML filtering and XSS protection</title>
	<atom:link href="http://dev.juokaz.com/php/html-filtering-and-xss-protection/feed" rel="self" type="application/rss+xml" />
	<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection</link>
	<description>Random ideas, scripts and facts</description>
	<lastBuildDate>Mon, 29 Mar 2010 18:47:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: star config web design sydney</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-8048</link>
		<dc:creator>star config web design sydney</dc:creator>
		<pubDate>Fri, 15 Jan 2010 05:44:01 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-8048</guid>
		<description>I agree with you html validation is very important when u building cms, i heared about TinyMCE editir, similar editor is used in joomla and mambo content managment system, and they using it in moodle2, it is quite well.

Thank you for your article it is really good, i liked it.</description>
		<content:encoded><![CDATA[<p>I agree with you html validation is very important when u building cms, i heared about TinyMCE editir, similar editor is used in joomla and mambo content managment system, and they using it in moodle2, it is quite well.</p>
<p>Thank you for your article it is really good, i liked it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sara</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-6235</link>
		<dc:creator>Sara</dc:creator>
		<pubDate>Tue, 27 Oct 2009 19:54:36 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-6235</guid>
		<description>Interesting point on web scrappers, For web scrappers i use python for simple things, but for larger projects i have used extractingdata.com &lt;a href=&quot;http://www.extractingdata.com/web%20scraper.htm&quot; rel=&quot;nofollow&quot;&gt;web scrapper&lt;/a&gt; which builds custom web scrappers and data extracting programs simple and fast</description>
		<content:encoded><![CDATA[<p>Interesting point on web scrappers, For web scrappers i use python for simple things, but for larger projects i have used extractingdata.com <a href="http://www.extractingdata.com/web%20scraper.htm" rel="nofollow">web scrapper</a> which builds custom web scrappers and data extracting programs simple and fast</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HTML filtering and XSS protection &#124; Juozas devBlog</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-583</link>
		<dc:creator>HTML filtering and XSS protection &#124; Juozas devBlog</dc:creator>
		<pubDate>Mon, 30 Mar 2009 05:08:45 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-583</guid>
		<description>[...] Here is the original: HTML filtering and XSS protection &#124; Juozas devBlog [...]</description>
		<content:encoded><![CDATA[<p>[...] Here is the original: HTML filtering and XSS protection | Juozas devBlog [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jamie Krasnoo</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-522</link>
		<dc:creator>Jamie Krasnoo</dc:creator>
		<pubDate>Thu, 26 Mar 2009 18:04:24 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-522</guid>
		<description>HTML Purifier is meant to scrub user input for use in a site so it won&#039;t return the  if it&#039;s included. It will scrub it out.

HTML Purifier is a bit of a pig but if you take the time to set up its cache you&#039;ll be rewarded with a performance increase.</description>
		<content:encoded><![CDATA[<p>HTML Purifier is meant to scrub user input for use in a site so it won&#8217;t return the  if it&#8217;s included. It will scrub it out.</p>
<p>HTML Purifier is a bit of a pig but if you take the time to set up its cache you&#8217;ll be rewarded with a performance increase.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juozas Kaziukenas&#8217; Blog: HTML filtering and XSS protection : Dragonfly Networks</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-464</link>
		<dc:creator>Juozas Kaziukenas&#8217; Blog: HTML filtering and XSS protection : Dragonfly Networks</dc:creator>
		<pubDate>Tue, 24 Mar 2009 04:51:59 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-464</guid>
		<description>[...] Kaziukenas has an example of how to keep you and your application&#8217;s data safe from prying eyes by filtering input with [...]</description>
		<content:encoded><![CDATA[<p>[...] Kaziukenas has an example of how to keep you and your application&#8217;s data safe from prying eyes by filtering input with [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juozas Kaziukenas&#8217; Blog: HTML filtering and XSS protection : WebNetiques, LLC : Website Developers in Minneapolis, MN</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-463</link>
		<dc:creator>Juozas Kaziukenas&#8217; Blog: HTML filtering and XSS protection : WebNetiques, LLC : Website Developers in Minneapolis, MN</dc:creator>
		<pubDate>Tue, 24 Mar 2009 04:49:33 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-463</guid>
		<description>[...] Kaziukenas has an example of how to keep you and your application&#8217;s data safe from prying eyes by filtering input with [...]</description>
		<content:encoded><![CDATA[<p>[...] Kaziukenas has an example of how to keep you and your application&#8217;s data safe from prying eyes by filtering input with [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim R. Wilson</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-454</link>
		<dc:creator>Jim R. Wilson</dc:creator>
		<pubDate>Mon, 23 Mar 2009 17:58:03 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-454</guid>
		<description>You&#039;re absolutely right that purifying potentially malicious HTML is a pain.  One solution that I particularly like is using a light markup language in lieu of allowing full-blown HTML.

A variety of suitable light markup languages exist, such as Markdown, Textile and those included with wiki systems (MediaWiki&#039;s wikitext comes to mind).  Of course, this generally comes as a tradeoff since most WYSIWYG editors focus on creating HTML to return to the server.

If your users can tolerate learning a light markup language, IMO that&#039;s a good way to go.</description>
		<content:encoded><![CDATA[<p>You&#8217;re absolutely right that purifying potentially malicious HTML is a pain.  One solution that I particularly like is using a light markup language in lieu of allowing full-blown HTML.</p>
<p>A variety of suitable light markup languages exist, such as Markdown, Textile and those included with wiki systems (MediaWiki&#8217;s wikitext comes to mind).  Of course, this generally comes as a tradeoff since most WYSIWYG editors focus on creating HTML to return to the server.</p>
<p>If your users can tolerate learning a light markup language, IMO that&#8217;s a good way to go.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juozas Kaziukenas&#8217; Blog: HTML filtering and XSS protection &#124; Development Blog With Code Updates : Developercast.com</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-452</link>
		<dc:creator>Juozas Kaziukenas&#8217; Blog: HTML filtering and XSS protection &#124; Development Blog With Code Updates : Developercast.com</dc:creator>
		<pubDate>Mon, 23 Mar 2009 16:42:11 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-452</guid>
		<description>[...] Kaziukenas has an example of how to keep you and your application&#8217;s data safe from prying eyes by filtering input with [...]</description>
		<content:encoded><![CDATA[<p>[...] Kaziukenas has an example of how to keep you and your application&#8217;s data safe from prying eyes by filtering input with [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juozas</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-429</link>
		<dc:creator>Juozas</dc:creator>
		<pubDate>Sun, 22 Mar 2009 12:56:11 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-429</guid>
		<description>Hi, thanks for your comment.

What about returning:

doctype &lt;html&gt;&lt;body&gt; return &lt;/body&gt;&lt;/html&gt;

? It shouldn&#039;t be that hard to implement :)</description>
		<content:encoded><![CDATA[<p>Hi, thanks for your comment.</p>
<p>What about returning:</p>
<p>doctype <html><body> return </body></html></p>
<p>? It shouldn&#8217;t be that hard to implement :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edward Z. Yang</title>
		<link>http://dev.juokaz.com/php/html-filtering-and-xss-protection/comment-page-1#comment-427</link>
		<dc:creator>Edward Z. Yang</dc:creator>
		<pubDate>Sun, 22 Mar 2009 08:59:56 +0000</pubDate>
		<guid isPermaLink="false">http://dev.juokaz.com/?p=396#comment-427</guid>
		<description>Hello!

Thanks for your blog post about HTML Purifier. You are right: HTML Purifier isn&#039;t currently able to return HTML with the head tag; it&#039;s just not what HTML Purifier is made for. Maybe in a future version it will have that functionality (probably when we build-in HTML5 parsing).</description>
		<content:encoded><![CDATA[<p>Hello!</p>
<p>Thanks for your blog post about HTML Purifier. You are right: HTML Purifier isn&#8217;t currently able to return HTML with the head tag; it&#8217;s just not what HTML Purifier is made for. Maybe in a future version it will have that functionality (probably when we build-in HTML5 parsing).</p>
]]></content:encoded>
	</item>
</channel>
</rss>
