On 20 May 2010 16:51, Al <news@xxxxxxxxxxxxx> wrote: > I'm not being clear. First pass is thru the blacklist, which effectually > tells hacker to not bother and totally deletes the entry. > > If the raw entry gets past the blacklist, it must then only contain my > whitelist tags. e.g., the two examples you cited were caught by the > whitelist parser. Ah, gotcha. That seems like a much better approach to me. But if the whitelist's going to stop the submission, then why bother with a blacklist at all? -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php