[Empeg-general] Re: HTML code in BBS post

frog51@empegbbs-noreply.merlins.org frog51 at empegbbs-noreply.merlins.org
Wed, 20 Mar 2002 09:54:00 GMT


Alternatively - html is one of the biggest security nightmares known to mankind
Currently, if you allow html in posts, you are effectively allowing control of the server, unless continous patching and hotfixing is done...and even then it won't be protected from some day-zero ish attacks.
At least limiting to UBBcode locks things down a lot.  And it's the best you can do without a full time security person.

Hey, we can still link to sites/files and input text in some colours.  It's not like we're stuck to 1 colour and no links