1228

Why can't we be just allowed to use use html and css to make threads?
by Irrational - 26 April, 2020 - 06:14 PM
This post is by a banned member (koba_lad) - Unhide
26 April, 2020 - 06:15 PM
XSS xd
jk, i tkink it could be nice but too difficult to implement
This post is by a banned member (Zombie) - Unhide
26 April, 2020 - 06:15 PM
Show me pls a single forum which allows html/css in a public post or for normal users which are non staff.
Ah yes, there's none for serveral reasons. Biggest reason is the security part. ![]() ONLY DISCORD: zombie#7550 (ID: 785571908267671613)
ONLY TELEGRAM: @zombie_dev I DONT DO MM. CONFIRM ALWAYS VIA PM ON CRACKED!
This post is by a banned member (Irrational) - Unhide
OP 26 April, 2020 - 06:23 PM
(This post was last modified: 26 April, 2020 - 06:23 PM by Irrational.)
(26 April, 2020 - 06:15 PM)Zombie Wrote: Show More Umm you are correct. But I was just wondering what is the security concern. JavaScript? Because HTML and CSS are just markup languages and can't do anything else. So if <script> is disabled??
You can like the post if it helped and have a good day.
![]()
This post is by a banned member (VAVE) - Unhide
(26 April, 2020 - 06:23 PM)Irrational Wrote: Show More <img> tags would have to be disabled too because you could use it like this: Code: <img style="display: none" src="random IpLogger url"> this would log the Ip of every user that opens the post without any notice edit: every tag that has the option to use an external source (src="random url") would have to be disabled because of this
This post is by a banned member (Cuchi) - Unhide
(26 April, 2020 - 06:15 PM)koba_lad Wrote: Show More Exactly, XSS. Lol, there are just too many ways to inject JS that it's better to disable all html/css (23 May, 2020 - 10:59 PM)amboss Wrote: Show More Yeah, also onerror and many other attributes ![]()
This post is by a banned member (AccountRepublic) - Unhide
24 May, 2020 - 06:18 PM
(23 May, 2020 - 10:59 PM)amboss Wrote: Show More yea, i was thinking about that too. but i've seen forums (don't remember quite well), only allows images from certain trusted source like imgbb, imgur. so why not use whitelisting?
DISCORD : AccountRepublic#9321 [ UID : 667336362885775360]
|
Create an account or sign in to comment | ||
You need to be a member in order to leave a comment | ||
Create an account
Sign up for a new account in our community. It's easy!
|
or |
Sign in
Already have an account? Sign in here.
|
Users browsing this thread: 1 Guest(s)