Solved

Searching for string inside preg_replace/preg_match findings

Posted on 2008-10-22
7
282 Views
Last Modified: 2013-12-13
I have on my website a forum that allows user input with bbcode style tags.
One of my issues recently has been users using CSRF on other pages on my website that aren't protected. And although I've started adding protection to each page, I feel it might be a faster immediate fix to prevent users including the string ".php" in any [img] tags, since the entire section of my website is coded in php.

I currently use the code attached below, but I am at a loss for how to ensure that ".php" does not occur within the tags. My other option is to ensure the extension of the link is a proper image extension. But again, no clue how to proceed.

Any help would be helpful :)
Thanks.
$s = preg_replace("/\[img\]([^\s'\"<>]+?)\[\/img\]/i", "<img style=\"border: none;\" src=\"\\1\" alt=\"img\" />", $s);

Open in new window

0
Comment
Question by:HigherIQ
  • 3
  • 2
  • 2
7 Comments
 
LVL 16

Expert Comment

by:sh0e
ID: 22784423
Does it have to be done in one line?  
Couldn't you just add another line to preg_replace .php with nothing?

$s = preg_replace("/\.php/ig", "");

Open in new window

0
 
LVL 16

Expert Comment

by:sh0e
ID: 22784430
typo
$s = preg_replace("/\.php/ig", "", $s);

Open in new window

0
 

Author Comment

by:HigherIQ
ID: 22784602
Unfortunately not, as the forum itself often references pages throughout the website with links etc.
I cannot just remove the ".php" from the whole text, as someone with an image may also have a valid link, and reason to have ".php" in the rest of the forum post.
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 
LVL 27

Accepted Solution

by:
ddrudik earned 500 total points
ID: 22785326

$s = preg_replace("/\[img\]((?:(?!\.php)[^\s'\"<>])+?)\[\/img\]/i", "<img style=\"border: none;\" src=\"\\1\" alt=\"img\" />", $s);

Open in new window

0
 

Author Comment

by:HigherIQ
ID: 22788378
ddrudik, that is absolutely perfect. I can now view it to see how it's used as well.

Thanks a lot :)
0
 
LVL 27

Expert Comment

by:ddrudik
ID: 22788553
Glad I could help.
0
 
LVL 27

Expert Comment

by:ddrudik
ID: 22789349
Thanks for the question and the points.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Developers of all skill levels should learn to use current best practices when developing websites. However many developers, new and old, fall into the trap of using deprecated features because this is what so many tutorials and books tell them to u…
These days socially coordinated efforts have turned into a critical requirement for enterprises.
The viewer will learn how to create and use a small PHP class to apply a watermark to an image. This video shows the viewer the setup for the PHP watermark as well as important coding language. Continue to Part 2 to learn the core code used in creat…
The viewer will learn how to create a basic form using some HTML5 and PHP for later processing. Set up your basic HTML file. Open your form tag and set the method and action attributes.: (CODE) Set up your first few inputs one for the name and …

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now