Stripping all client-side script

From: Mike Torres (mit4@yahoo.com)
Date: 10/25/02


From: mit4@yahoo.com (Mike Torres)
Date: 25 Oct 2002 13:31:54 -0700


Hey folks -

I am looking for a class library (or some code) that can strip
client-side script from an HTML encoded string, and after hours of
searching the net, I haven't found anything.

I want to protect against scripting attacks by stripping all possible
script out of HTML input (using RichTextBox at www.richtextbox.com)

So, for example, it would need to strip:

<script *></script>
javascript:XXX
onLoad="" (really onXXX="")

and probably more (for example style="" for embedding behaviors, etc.)

Does anyone know where I can find such code? I am not a
Jscript/VBscript wiz, so I want to make sure I am covering all the
bases.

Thanks,
Mike



Relevant Pages

  • Re: .Net Equivilant for sqlcmd or osql
    ... applications like SQL Management Studio work. ... Also, you do not have to strip the comments, it works just fine, ... Read EACH line into a string buffer. ... Read your script file and split it on the GO ...
    (microsoft.public.dotnet.languages.csharp)
  • [OT] FOAK: Regexp experts.
    ... I'm trying to set up a script to strip out URL's from the body of a ... Cab:^) - argue's like a girl ... GSX 1400 ...
    (uk.rec.motorcycles)
  • WMI is not seeing specific services on some servers
    ... The script runs well; however, on a few servers, even though both ... WMI reports PatchLink as missing. ... Dim x, strIP, varSubNet ...
    (microsoft.public.scripting.vbscript)
  • WMI sees services correctly on most servers but not all...
    ... The script runs well; however, on a few servers, even though both ... WMI reports PatchLink as missing. ... Dim x, strIP, varSubNet ...
    (microsoft.public.win32.programmer.wmi)
  • Fwd: Delete lines containing a specific word
    ... I forgot to add that the lines to strip are in present case of the type of the ... In present case each three-lines block is followed by line renumbering (7007, ... the script is simply to strip the lines ... Find them fast with Yahoo! ...
    (comp.lang.python)