That is neat, but you'd also need to s/// ascii codes like:
\x3Ca href="#" onclick="alert('a ha')">boo\x3C/a>and no doubt lots of other tricks. It's generally better to strip everything out than to try and keep up with the kids, i've found.
update: completely wrong, as jeffa was tactful enough to point out privately. the translation of the ascii character happens in perl, not in the browser. i tested with a qq|| string and didn't look at the html source. slap.
In reply to Re: (jeffa) Re: Stopping the abuse
by thpfft
in thread Stopping the abuse
by rezoraith
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |