Deprecated: explode(): Passing null to parameter #2 ($string) of type string is deprecated in /var/www/html/src/core/services/AnalyticsService.php on line 109
HTML sanitization tests - Forum - The Cyberix Network

The Cyberix Network

The sophisticated man's creative playground.

deeply appreciate it <3
New site released. Things may or may not be broken. Let us know if you see something that is.

HTML sanitization tests

| Oct 05, 2025 1:43 PM No.1067 [Report]

ONE: </td></tr></table></center>

THIS IS A THREAD

</p>

TWO:

</p>

THREE: <table width="5000"><tr><td>This forces horizontal scroll

FOUR: <marquee>

<blink>

<h1><h1><h1><h1></p> <p>FIVE: <div style="position:absolute; top:0; left:0; width:9999px; height:9999px; background:url('denied:https://cy-x.net/assets/images/cyberixbanner.png')"></div></p> <p></center></body></html><body><h1>New page starts here</p>

| Oct 05, 2025 3:20 PM No.1068 [Report]

<marquee direction="right">What are you experimenting with man?!</marquee>

| Oct 05, 2025 3:25 PM No.1069 [Report]

WHAT ARE YOU DOING!!!
THIS IS BULLSHIT!!!
OOOOO OOOOO OOOOO

<style>@keyframes blink {50% {opacity: 0;}}</style>

<marquee direction="right" scrollamount="300">ajspdjpowjpjwapdnOIBOBPDW</marquee>

image
| Oct 05, 2025 3:31 PM No.1070 [Report]

i think we're good now

| Oct 05, 2025 3:37 PM No.1071 [Report]
has been kilt.

N o t h i n g i s s t o p p i n g y o u f r o m h a v i n g c o l o r e d t e x t , t h o u g h

| Oct 06, 2025 7:58 AM No.1087 [Report]

What's the rationale behind blocking <div>? As far as I know, it doesn't do anything more than other elements.

| Oct 06, 2025 8:13 AM No.1088 [Report]

Random idea if you want to allow arbitrary HTML posting: put every post in an iframe.

| Oct 06, 2025 3:27 PM No.1098 [Report]

I can't into properly sanitizing HTML apparently so I killed

and . I will most likely need to make this system more intricate</p> <p>Colored text should remain though</p>
| Oct 06, 2025 3:27 PM No.1099 [Report]

>put every post in an iframe.

Could consider it but I feel like that'd have such a horrible performance hit that I don't know if its worth it. I'll look into that anyway though

| Oct 06, 2025 3:31 PM No.1100 [Report]

There's a lot of things wrong with my text formatter. All user text, both articles and posts are run through this single formatting system.

Recent changes fucked up where newlines/breaks are placed, my wonderful attempt at allowing both BBCode and Markdown work but the Markdown implementation I'm using is interfering with what I'm doing to properly break lines
HTML sanitization was laughably weak and probably still is now. I think I might resort to just looking at HTML standards from 30 years ago and not allowing anything newer. I was using for font colors when still works fine.

I'll keep working on this

| Oct 06, 2025 4:47 PM No.1102 [Report]

>There's a lot of things wrong with my text formatter.

spoke too fuckin soon and I quadruple-posted

Post a Reply

Anonymous attachments will always expire 15 minutes after upload.