{
  "attachments": [],
  "comments_archived": true,
  "date": "2002-09-26T07:52:05.000Z",
  "layout": "post",
  "title": "MTCleanHTMLPlugin - borrowing a page from LJ, literally.",
  "wordpress_id": 271,
  "wordpress_slug": "ooobif",
  "wordpress_url": "http://www.decafbad.com/blog/?p=271",
  "year": "2002",
  "month": "09",
  "day": "26",
  "isDir": false,
  "slug": "ooobif",
  "type": "entry",
  "postName": "2002-09-26-ooobif",
  "html": "<p>Tonight, I borrowed <a href=\"http://www.decafbad.com/twiki/bin/view/Main/LiveJournal\">LiveJournal</a>'s comment filtering code and made it into a <a href=\"http://www.decafbad.com/twiki/bin/view/Main/MovableType\">MovableType</a> plugin: <a href=\"http://www.decafbad.com/twiki/bin/view/Main/MTCleanHTMLPlugin\">MTCleanHTMLPlugin</a></p>\n<p>After all that ramble about having open system and not having been the victim of an exploit, <a href=\"http://www.decafbad.com/twiki/bin/view/Main/SamRuby\">SamRuby</a> inadvertently revealed one gapingly wide hole for me.  Not that he did anything to exploit it - I just realized that a bug he tripped over could be used for more nefarious purposes.  So, I closed the hole, and after a bit of quick research went a bit further and made a new <a href=\"http://www.decafbad.com/twiki/bin/view/Main/MovableType\">MovableType</a> plugin.  Borrowing <a href=\"http://www.decafbad.com/twiki/bin/view/Main/LiveJournal\">LiveJournal</a>'s code yields a filter which strips out most nasty <span style=\"background : [#FFFFCE](/tag/FFFFCE);\"><a href=\"http://www.decafbad.com/twiki/bin/edit/Main/JavaScript?topicparent=Main.FilterData\"><b>?</b></a><font color=\"#0000FF\">JavaScript</font></span> exploits, and attempts to close tags left lazily open.</p>\n<p>Hope someone finds a use for it.</p>\n<!--more-->\n\n\n<p>shortname=ooobif</p>\n<div id=\"comments\" class=\"comments archived-comments\"><h3>Archived Comments</h3>\n<ul class=\"comments\">\n<li class=\"comment\" id=\"comment-221088943\">\n<div class=\"meta\">\n<div class=\"author\">\n<a class=\"avatar image\" rel=\"nofollow\" href=\"http://www.szymona.net/\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=f194d709fe039e6c95d2aa3eb3f9b0f2&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\" width=\"\" height=\"\"></a>\n<a class=\"avatar name\" rel=\"nofollow\" href=\"http://www.szymona.net/\">Jeff Szymona</a>\n</div>\n\n\n<p><a href=\"#comment-221088943\" class=\"permalink\"><time datetime=\"2002-09-26T04:24:27\">2002-09-26T04:24:27</time></a></p>\n</div>\n\n\n<div class=\"content\">Should this tag be wrapped around the TrackBack pings also?</div>\n\n\n</li>\n<li class=\"comment\" id=\"comment-221088945\">\n<div class=\"meta\">\n<div class=\"author\">\n<a class=\"avatar image\" rel=\"nofollow\" href=\"http://www.decafbad.com\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=2ac2cffd36ada8c734b90e02a1e5c1ac&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\" width=\"\" height=\"\"></a>\n<a class=\"avatar name\" rel=\"nofollow\" href=\"http://www.decafbad.com\">l.m.orchard</a>\n</div>\n\n\n<p><a href=\"#comment-221088945\" class=\"permalink\"><time datetime=\"2002-09-26T13:06:12\">2002-09-26T13:06:12</time></a></p>\n</div>\n\n\n<div class=\"content\">Hmm, that might not be such a bad idea.  Really, wherever you allow content submitted by someone other than you, you should use this tag (or something like it).</div>\n\n\n</li>\n<li class=\"comment\" id=\"comment-221088946\">\n<div class=\"meta\">\n<div class=\"author\">\n<a class=\"avatar image\" rel=\"nofollow\" href=\"http://www.szymona.net/\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=f194d709fe039e6c95d2aa3eb3f9b0f2&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\" width=\"\" height=\"\"></a>\n<a class=\"avatar name\" rel=\"nofollow\" href=\"http://www.szymona.net/\">Jeff Szymona</a>\n</div>\n\n\n<p><a href=\"#comment-221088946\" class=\"permalink\"><time datetime=\"2002-09-26T13:56:57\">2002-09-26T13:56:57</time></a></p>\n</div>\n\n\n<div class=\"content\">Well, I didn't think at first, but at least what I do is include a call to the cgi with php, so it wouldn't work anyway.  Maybe the logic could be (or already is) included there.  I haven't looked at the source yet, but then I'm just learning Perl now, so I don't know if I would identify the right spot yet :)</div>\n\n\n</li>\n<li class=\"comment\" id=\"comment-221088947\">\n<div class=\"meta\">\n<div class=\"author\">\n<a class=\"avatar image\" rel=\"nofollow\" href=\"http://www.10500bc.org\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=6492f173a7059ece309f7d670ff44e95&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\" width=\"\" height=\"\"></a>\n<a class=\"avatar name\" rel=\"nofollow\" href=\"http://www.10500bc.org\">nf0</a>\n</div>\n\n\n<p><a href=\"#comment-221088947\" class=\"permalink\"><time datetime=\"2002-09-26T14:40:24\">2002-09-26T14:40:24</time></a></p>\n</div>\n\n\n<div class=\"content\">Thanks for another good one!</div>\n\n\n</li>\n<li class=\"comment\" id=\"comment-221088948\">\n<div class=\"meta\">\n<div class=\"author\">\n<a class=\"avatar image\" rel=\"nofollow\" href=\"http://www.inluminent.com/weblog/\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=489902e4dda27edd54b350d46b9d19c1&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\" width=\"\" height=\"\"></a>\n<a class=\"avatar name\" rel=\"nofollow\" href=\"http://www.inluminent.com/weblog/\">john</a>\n</div>\n\n\n<p><a href=\"#comment-221088948\" class=\"permalink\"><time datetime=\"2002-09-27T11:40:40\">2002-09-27T11:40:40</time></a></p>\n</div>\n\n\n<div class=\"content\">l.m. so, I'm looking at the instructions and where I see this:\n.\n|-- README\n|-- extdir\n|   `-- MT\n|       `-- decafbad\n|           `-- cleanhtml.pm\n`-- plugins\n`-- cleanhtml.pl\nI'm perplexed.  I don't have an extdir directory.  I have an extlib directory, but it doesn't have an MT in it...\nso, where does all of this stuff go, off your root MT installation?\nThanks,\nJohn\n(I really just want to be an end user, but find myself being a hacker, in that I'm being forced to install hacks on a piece of software in a language I know very little about.)</div>\n\n\n</li>\n<li class=\"comment\" id=\"comment-221088949\">\n<div class=\"meta\">\n<div class=\"author\">\n<a class=\"avatar image\" rel=\"nofollow\" href=\"http://www.10500bc.org\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=6492f173a7059ece309f7d670ff44e95&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\" width=\"\" height=\"\"></a>\n<a class=\"avatar name\" rel=\"nofollow\" href=\"http://www.10500bc.org\">nf0</a>\n</div>\n\n\n<p><a href=\"#comment-221088949\" class=\"permalink\"><time datetime=\"2002-09-27T12:08:02\">2002-09-27T12:08:02</time></a></p>\n</div>\n\n\n<div class=\"content\">John,\nyou can put it under extlib. If you don't have an MT subdir in there then you can just create one, then another subdir called decafbad. Also if you don't have the plugins directory in your root MT folder you'll have to create that one as well. Hope that helps</div>\n\n\n</li>\n<li class=\"comment\" id=\"comment-221088950\">\n<div class=\"meta\">\n<div class=\"author\">\n<a class=\"avatar image\" rel=\"nofollow\" href=\"http://www.decafbad.com\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=2ac2cffd36ada8c734b90e02a1e5c1ac&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\" width=\"\" height=\"\"></a>\n<a class=\"avatar name\" rel=\"nofollow\" href=\"http://www.decafbad.com\">l.m.orchard</a>\n</div>\n\n\n<p><a href=\"#comment-221088950\" class=\"permalink\"><time datetime=\"2002-09-27T13:16:18\">2002-09-27T13:16:18</time></a></p>\n</div>\n\n\n<div class=\"content\">D'oht, good catch John - it's supposed to be \"extlib\", not \"extdir\".  I'll see about updating that today!  Sorry about that!</div>\n\n\n</li>\n</ul>\n\n\n</div>\n\n\n",
  "body": "Tonight, I borrowed <a href=\"http://www.decafbad.com/twiki/bin/view/Main/LiveJournal\">LiveJournal</a>'s comment filtering code and made it into a <a href=\"http://www.decafbad.com/twiki/bin/view/Main/MovableType\">MovableType</a> plugin: <a href=\"http://www.decafbad.com/twiki/bin/view/Main/MTCleanHTMLPlugin\">MTCleanHTMLPlugin</a>\r\n<br /><br />\r\nAfter all that ramble about having open system and not having been the victim of an exploit, <a href=\"http://www.decafbad.com/twiki/bin/view/Main/SamRuby\">SamRuby</a> inadvertently revealed one gapingly wide hole for me.  Not that he did anything to exploit it - I just realized that a bug he tripped over could be used for more nefarious purposes.  So, I closed the hole, and after a bit of quick research went a bit further and made a new <a href=\"http://www.decafbad.com/twiki/bin/view/Main/MovableType\">MovableType</a> plugin.  Borrowing <a href=\"http://www.decafbad.com/twiki/bin/view/Main/LiveJournal\">LiveJournal</a>'s code yields a filter which strips out most nasty <span style='background : #FFFFCE;'><a href=\"http://www.decafbad.com/twiki/bin/edit/Main/JavaScript?topicparent=Main.FilterData\"><b>?</b></a><font color=\"#0000FF\">JavaScript</font></span> exploits, and attempts to close tags left lazily open.\r\n<br /><br />\r\nHope someone finds a use for it.\r\n<!--more-->\r\nshortname=ooobif\r\n\r\n<div id=\"comments\" class=\"comments archived-comments\">\r\n            <h3>Archived Comments</h3>\r\n            \r\n        <ul class=\"comments\">\r\n            \r\n        <li class=\"comment\" id=\"comment-221088943\">\r\n            <div class=\"meta\">\r\n                <div class=\"author\">\r\n                    <a class=\"avatar image\" rel=\"nofollow\" \r\n                       href=\"http://www.szymona.net/\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=f194d709fe039e6c95d2aa3eb3f9b0f2&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\"/></a>\r\n                    <a class=\"avatar name\" rel=\"nofollow\" \r\n                       href=\"http://www.szymona.net/\">Jeff Szymona</a>\r\n                </div>\r\n                <a href=\"#comment-221088943\" class=\"permalink\"><time datetime=\"2002-09-26T04:24:27\">2002-09-26T04:24:27</time></a>\r\n            </div>\r\n            <div class=\"content\">Should this tag be wrapped around the TrackBack pings also?</div>\r\n            \r\n        </li>\r\n    \r\n        <li class=\"comment\" id=\"comment-221088945\">\r\n            <div class=\"meta\">\r\n                <div class=\"author\">\r\n                    <a class=\"avatar image\" rel=\"nofollow\" \r\n                       href=\"http://www.decafbad.com\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=2ac2cffd36ada8c734b90e02a1e5c1ac&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\"/></a>\r\n                    <a class=\"avatar name\" rel=\"nofollow\" \r\n                       href=\"http://www.decafbad.com\">l.m.orchard</a>\r\n                </div>\r\n                <a href=\"#comment-221088945\" class=\"permalink\"><time datetime=\"2002-09-26T13:06:12\">2002-09-26T13:06:12</time></a>\r\n            </div>\r\n            <div class=\"content\">Hmm, that might not be such a bad idea.  Really, wherever you allow content submitted by someone other than you, you should use this tag (or something like it).</div>\r\n            \r\n        </li>\r\n    \r\n        <li class=\"comment\" id=\"comment-221088946\">\r\n            <div class=\"meta\">\r\n                <div class=\"author\">\r\n                    <a class=\"avatar image\" rel=\"nofollow\" \r\n                       href=\"http://www.szymona.net/\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=f194d709fe039e6c95d2aa3eb3f9b0f2&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\"/></a>\r\n                    <a class=\"avatar name\" rel=\"nofollow\" \r\n                       href=\"http://www.szymona.net/\">Jeff Szymona</a>\r\n                </div>\r\n                <a href=\"#comment-221088946\" class=\"permalink\"><time datetime=\"2002-09-26T13:56:57\">2002-09-26T13:56:57</time></a>\r\n            </div>\r\n            <div class=\"content\">Well, I didn't think at first, but at least what I do is include a call to the cgi with php, so it wouldn't work anyway.  Maybe the logic could be (or already is) included there.  I haven't looked at the source yet, but then I'm just learning Perl now, so I don't know if I would identify the right spot yet :)</div>\r\n            \r\n        </li>\r\n    \r\n        <li class=\"comment\" id=\"comment-221088947\">\r\n            <div class=\"meta\">\r\n                <div class=\"author\">\r\n                    <a class=\"avatar image\" rel=\"nofollow\" \r\n                       href=\"http://www.10500bc.org\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=6492f173a7059ece309f7d670ff44e95&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\"/></a>\r\n                    <a class=\"avatar name\" rel=\"nofollow\" \r\n                       href=\"http://www.10500bc.org\">nf0</a>\r\n                </div>\r\n                <a href=\"#comment-221088947\" class=\"permalink\"><time datetime=\"2002-09-26T14:40:24\">2002-09-26T14:40:24</time></a>\r\n            </div>\r\n            <div class=\"content\">Thanks for another good one!</div>\r\n            \r\n        </li>\r\n    \r\n        <li class=\"comment\" id=\"comment-221088948\">\r\n            <div class=\"meta\">\r\n                <div class=\"author\">\r\n                    <a class=\"avatar image\" rel=\"nofollow\" \r\n                       href=\"http://www.inluminent.com/weblog/\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=489902e4dda27edd54b350d46b9d19c1&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\"/></a>\r\n                    <a class=\"avatar name\" rel=\"nofollow\" \r\n                       href=\"http://www.inluminent.com/weblog/\">john</a>\r\n                </div>\r\n                <a href=\"#comment-221088948\" class=\"permalink\"><time datetime=\"2002-09-27T11:40:40\">2002-09-27T11:40:40</time></a>\r\n            </div>\r\n            <div class=\"content\">l.m. so, I'm looking at the instructions and where I see this:\r\n\r\n.\r\n|-- README\r\n|-- extdir\r\n|   `-- MT\r\n|       `-- decafbad\r\n|           `-- cleanhtml.pm\r\n`-- plugins\r\n    `-- cleanhtml.pl\r\n\r\n\r\nI'm perplexed.  I don't have an extdir directory.  I have an extlib directory, but it doesn't have an MT in it...\r\n\r\nso, where does all of this stuff go, off your root MT installation?\r\n\r\nThanks,\r\nJohn\r\n\r\n(I really just want to be an end user, but find myself being a hacker, in that I'm being forced to install hacks on a piece of software in a language I know very little about.)</div>\r\n            \r\n        </li>\r\n    \r\n        <li class=\"comment\" id=\"comment-221088949\">\r\n            <div class=\"meta\">\r\n                <div class=\"author\">\r\n                    <a class=\"avatar image\" rel=\"nofollow\" \r\n                       href=\"http://www.10500bc.org\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=6492f173a7059ece309f7d670ff44e95&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\"/></a>\r\n                    <a class=\"avatar name\" rel=\"nofollow\" \r\n                       href=\"http://www.10500bc.org\">nf0</a>\r\n                </div>\r\n                <a href=\"#comment-221088949\" class=\"permalink\"><time datetime=\"2002-09-27T12:08:02\">2002-09-27T12:08:02</time></a>\r\n            </div>\r\n            <div class=\"content\">John,\r\nyou can put it under extlib. If you don't have an MT subdir in there then you can just create one, then another subdir called decafbad. Also if you don't have the plugins directory in your root MT folder you'll have to create that one as well. Hope that helps</div>\r\n            \r\n        </li>\r\n    \r\n        <li class=\"comment\" id=\"comment-221088950\">\r\n            <div class=\"meta\">\r\n                <div class=\"author\">\r\n                    <a class=\"avatar image\" rel=\"nofollow\" \r\n                       href=\"http://www.decafbad.com\"><img src=\"http://www.gravatar.com/avatar.php?gravatar_id=2ac2cffd36ada8c734b90e02a1e5c1ac&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png\"/></a>\r\n                    <a class=\"avatar name\" rel=\"nofollow\" \r\n                       href=\"http://www.decafbad.com\">l.m.orchard</a>\r\n                </div>\r\n                <a href=\"#comment-221088950\" class=\"permalink\"><time datetime=\"2002-09-27T13:16:18\">2002-09-27T13:16:18</time></a>\r\n            </div>\r\n            <div class=\"content\">D'oht, good catch John - it's supposed to be \"extlib\", not \"extdir\".  I'll see about updating that today!  Sorry about that!</div>\r\n            \r\n        </li>\r\n    \r\n        </ul>\r\n    \r\n        </div>\r\n    ",
  "parentPath": "./content/posts/archives/2002",
  "path": "2002/09/26/ooobif",
  "summary": "Tonight, I borrowed LiveJournal's comment filtering code and made it into a MovableType plugin: MTCleanHTMLPlugin\nAfter all that ramble about having open system and not having been the victim of an exploit, SamRuby inadvertently revealed one gapingly wide hole for me.  Not that he did anything to exploit it - I just realized that a bug he tripped over could be used for more nefarious purposes.  So, I closed the hole, and after a bit of quick research went a bit further and made a new MovableType plugin.  Borrowing LiveJournal's code yields a filter which strips out most nasty ?JavaScript exploits, and attempts to close tags left lazily open.\nHope someone finds a use for it.",
  "needsBuild": true,
  "prevPostPath": "2002/09/25/ooobie",
  "prevPostTitle": "Automated Pingback vs Human Talkback - Which is more humane?",
  "nextPostPath": "2002/09/27/ooobig",
  "nextPostTitle": "Packaging tweak to MTCleanHTMLPlugin"
}