10 months ago
Signature/Profile Coding Insecurity with HTML

As someone who has been though a lot of sites that use html for signature and profile coding, specifically pet sites, I'd like to suggest using BB code instead.

HTML is very insecure, it is easy to hide malicious code in html and its very easy to break by accident.

I have seen another newer pet site use html and had it break everyone's post underneath it.

Report
10 months ago
Recall
The Star
Dev'ing around.
61
61 Achievements
Starter Rank 1
Arena Rank 2

Neutral but mostly leaning to support.

BBCode is still insecure if it is implememted poorly, the reason is that bbcode gets translated into HTML when viewed on preview/after saving which means exploits such as XSS can still slip through.

Nowadays modern secure applications do not allow usage of HTML in complete freedom which means ignoring the tags/attributes by the parser which can carry malicious code.

Regarding breaking by accident you can also do it with bbcode, if you are willing enough :)

I would like to see bbcode since it is what I'm used to the most when it comes to such websites (though im a webdev)

(Edited)
Report
Quote
10 months ago

@Recall

Thank you for the info. I'm not an expert as I have not really programed much myself!

Report
Quote
10 months ago
Tserin
he/him, ae/aer
22
22 Achievements
Forum Rank 3
Forum Threads: 51
Forum Comments: 547

Support both for the security concerns and because honestly, BBCode is a lot easier to work with. I have experience with HTML and don't find it difficult at all, but BBCode is just so much nicer to deal with in this kind of context and is also more familiar to a lot of petsite players who will be using it.

Report
Quote

Cooking/Free Crafting ~ Wolf Leveling

Tip: You can search a username in the Name field of the FM too!

Do not send me friend requests or random PMs.

Unsubscribe from Post
Subscribe to Thread
Recent
Subscribed
My posts
Recent Topics
1 2 3 4 5 ... 10
Subscribed
You are not subscribed to any threads.
My Threads
You do not have any threads.
Trees
Music
Shuffle
Theme
Enable to have Music selection based site activities.
Repeat
Enable to repeat the current song.
Volume
Dismiss
Not interested in music? Permanently dismiss this music player.
Bathing on an Arturas
Boil 'em, Mash 'em
Canictonis Crossing
Dreaming About You
Embarking
Fields of Loria
First Snow
Follow the Leader
Good Morning, Challengers
Haunted Cave
Into the Deep
Lone Wolf
Moonsblessings
Mosey Through the Forums
Nothing but Time
Play Date With Nana
Queueing Up
Silly Walk
Sleepy Wolves
Sploosh
Sunken Melody
The Mighty Remain
Through Goldsea
What to Buy?