View Single Post
Old 03-16-2019, 10:33 PM   #6
KevinH
Sigil Developer
KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.
 
Posts: 8,807
Karma: 6000000
Join Date: Nov 2009
Device: many
I know it sounds silly, but html and xml allowed people to craft their own entity definitions and people actually crafted recursive entities that were used to attack websites and browsers. There is actually a lot of code to prevent evilly crafted named entities. The move to just numeric entities has made validating and expanding entities much easier and safer and help to restrict attack vectors.
KevinH is online now   Reply With Quote