Jump to content

Why Is Html So Bad


Recommended Posts

I have been thinking about this for a while.

Why is HTML so bad to set to on when configuring guestbooks etc?

 

In my guestbook it says this:

HTML code is disabled

Smilies are ON

AGCode is ON

 

Wouldnt it be better to allow HTML instead of AGCode? HTML is atleast something most people have heard about.

 

By the way, what is AGCode?

 

-Thomas

Link to post
Share on other sites

Thomas, if you allow your visitors to use HTML in your guestbook/forums/etc, someone might code an exploit for a known security issue with a specific browser, for example. That's why HTML is usually disabled in guestbooks, forums and stuff that allows user input.

Link to post
Share on other sites

Yes, it can. And it has happened some times with phpBB and it's BBCode implementation, and even with Invision Power Board.

But it's much easier to fix a bug in the "code-language" implementation than in Internet Explorer, for example. :D

 

A security threat in the "code-language" is solved by simply patching/upgrading the guestbook/forum software, while a security threat in a browser is only solved if all your visitors patch/upgrade their software - which one do you think will be easier? ;)

Link to post
Share on other sites

Thomas, if you are using the advanced guestbook,

when someone goes to sign your guestbook

there is a link below AGCode is ON

 

HTML code is disabled

Smilies are ON

AGCode is ON

 

Show legend

that will show how to use them.

 

 

Hope this helps :D

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...