php stripping angled brackets - Help!

Discussion in 'PHP' started by rolysatch, Oct 25, 2008.

  1. #1
    hi

    i have a php program i use to make posts to my wordpress blogs. all of a sudden i'm getting strange results when posting to my blogs. the posts are being posted without the < and > parts of (angled brackets) and " (quotation marks) of html in the posts, everything else is normal.

    e.g. post should be: <p><a href="http://somesite.com">hello</a></p>

    but i am getting: pa href=http://somesite.comhello ap

    i recently upgraded apache to 2.2.10 and rebuilt php/mysql etc and i'm wondering if there is some new security fix that has something to do with it. or alternatively does anyone know a function in php.ini i may have changed without realising that may have caused the angled brackets to be stripped from my posts?

    this is something related to the server/php/apache as opposed to the script or wordpress as that has been working succesfully for a long time without problems and i haven't changed the wordpress version.

    any help appreciated

    thanks in advance

    roland
     
    rolysatch, Oct 25, 2008 IP
  2. Kyosys

    Kyosys Peon

    Messages:
    226
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #2
    sounds like a retarded way of preventing XSS
     
    Kyosys, Oct 25, 2008 IP
  3. rolysatch

    rolysatch Active Member

    Messages:
    131
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #3
    oh i see, thanks for the reply. i can manually post from within wordpress and it doesn't strip those characters. i had a look at what the new apache update 2.2.10 was, and there's a change it's mentions regarding XSS:

    *) SECURITY: CVE-2008-2939 (cve.mitre.org)
    mod_proxy_ftp: Prevent XSS attacks when using wildcards in the path of
    the FTP URL. Discovered by Marc Bevand of Rapid7. [Ruediger Pluem]

    i'm not sure if that is where my problem lies?
     
    rolysatch, Oct 25, 2008 IP
  4. Kyosys

    Kyosys Peon

    Messages:
    226
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #4
    no, that has nothign to do with your problem
     
    Kyosys, Oct 25, 2008 IP
  5. rolysatch

    rolysatch Active Member

    Messages:
    131
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #5
    oh ok, thanks again. i did upgrade the kernel on my centos server, but i'm guessing that has nothing to do with it. i'm confused then. i'll take another look at my php.ini and see if there's anything there that i missed.
     
    rolysatch, Oct 25, 2008 IP