Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

cross script attacks

Status
Not open for further replies.

lucidtech

IS-IT--Management
Jan 17, 2005
267
US
I am building a social network site and I want to allow users to post object tags (ie videos from youtube, etc.) but I want to prevent my server from running an javascript that may be embedded in the posts. Bascially it's like the comment system on MySpace, and I know myspace has accomplished this somehow, but I'm not even sure where to begin.

Basically I just want my site to only run the javascript I have linked to on my server and disable any other javascript that users may post via comments, either by adding javascript code in the comment box or adding an object tag which has javascript in its content.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top