The risk being taken in "harmless" tags is in the attributes, particularly the event handlers.Highway of Life wrote:Not really, in phpBB2, you have a config field that allows only the HTML that you want allowed on your forum. For instance, tables and div tags are pretty much harmless.robertmf wrote: Isn't allowing html in posts generally considered a security risk ?
Suspecting beta release very very soon!
Forum rules
Discussion of general topics related to the new release and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Discussion of general topics related to the new release and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Re: Suspecting beta release very very soon!
"I hate trolls!" - Willow Ufgood
Re: Suspecting beta release very very soon!
I think you just said the opposite of what you meant. That's a double negative.SamG wrote: It's not creepy if it's not finished.
Your statement equates to: "It's creepy if it's finished."
I got a postcard from my friend George. It was a satellite photo of the entire Earth. On the back he wrote, "Wish you were here."
Re: Suspecting beta release very very soon!
It's not a double negative.. If it's not creepy when it's not finished, it doesn't mean it is creepy when it is 
- SHS`
- Registered User
- Posts: 1628
- Joined: Wed Jul 04, 2001 9:13 am
- Location: The Boonies, Hong Kong
- Contact:
Re: Suspecting beta release very very soon!
Whilst that is true in the Queen's English, who knows when it's American English... how many times have you seen "I could care less", when in the Queen's English it should be "I couldn't care less".spambot wrote: It's not a double negative.. If it's not creepy when it's not finished, it doesn't mean it is creepy when it is![]()
Jonathan “SHS`” Stanley • 史德信
phpBB™ 3.1.x, Bug/Security trackers
phpBB™ Bertie Bear 3.0 — prosilver Edition! • Asking Questions The Smart Way
phpBB™ 3.1.x, Bug/Security trackers
phpBB™ Bertie Bear 3.0 — prosilver Edition! • Asking Questions The Smart Way
Re: Suspecting beta release very very soon!
true, or in mathematical notationspambot wrote: If it's not creepy when it's not finished, it doesn't mean it is creepy when it is
a =>b does not mean !a => !b
however a =>b does mean !b => !a
Re: Suspecting beta release very very soon!
How about "There ain't no way"SHS` wrote: Whilst that is true in the Queen's English, who knows when it's American English... how many times have you seen "I could care less", when in the Queen's English it should be "I couldn't care less".![]()
- NNO-Stephen
- Registered User
- Posts: 398
- Joined: Fri May 23, 2003 12:47 am
- Location: Tulsa, Oklahoma
- Contact:
Re: Suspecting beta release very very soon!
that's just it though, if your site for instance, reads out of the phpBB database for something and it doesn't use the BBCode parser at all, then it can interpret HTML as HTML, and display it as such, whereas BBCode would be displayed as just text.Lieutenant Clone wrote: The BBcode seems diverse enough that html wouldnt be needed. I dont see if used very often either... might be good for the admin though. It does cut down on parsing time by taking it out too, instead of finding what is allowed.
thats the problem, not the inability to display certain things because BBCode doesn't support it
and it's only a security risk if the board admin is a friggin' idiot and enables script and object and a ton of other *beep* like that which people shouldn't need under any circumstances.
- EXreaction
- Registered User
- Posts: 1555
- Joined: Sat Sep 10, 2005 2:15 am
Re: Suspecting beta release very very soon!
Ya, and when someone says "All but..."SHS` wrote: Whilst that is true in the Queen's English, who knows when it's American English... how many times have you seen "I could care less", when in the Queen's English it should be "I couldn't care less".![]()
Like "He is all but dead"...shouldn't that mean that is is everything except dead? Not over here...it means he is dead.
- dhn
- Registered User
- Posts: 1518
- Joined: Wed Jul 04, 2001 8:10 am
- Location: Around the corner
- Contact:
Re: Suspecting beta release very very soon!
You just described 95% of the board admins out there.NNO-Stephen wrote: and it's only a security risk if the board admin is a friggin' idiot and enables script and object and a ton of other *beep* like that which people shouldn't need under any circumstances.
- robertmf
- Registered User
- Posts: 52
- Joined: Wed Jul 23, 2003 5:20 pm
- Location: In PA, 55 min. via commuter RR outside Filthadelphia
- Contact:
Re: Suspecting beta release very very soon!
... and the other 5% are liars !!-dhn wrote:You just described 95% of the board admins out there.NNO-Stephen wrote: and it's only a security risk if the board admin is a friggin' idiot and enables script and object and a ton of other *beep* like that which people shouldn't need under any circumstances.