Re: Security Issues

From: Date: Wed, 25 Jul 2001 21:58:31 +0000
Subject: Re: Security Issues
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-61003@lists.php.net to get a copy of this message
On Tue, Jul 24, 2001 at 08:27:21PM -0700, Zeev Suraski wrote: > Setting register_globals to off (which is highly recommended) would prevent > PHP from defining form variables as global variables. For quite a while, > since the PHP 3.0 times, PHP provided an alternative way of accessing > variables - using special designated arrays - $HTTP_POST_VARS, > $HTTP_GET_VARS, and so forth. As of PHP 4.0.3 (IIRC), these variables are > always defined, and are protected (to a degree) by PHP. Setting > register_globals to off effectively prevents any outer access to your > namespace, outside $HTTP_*_VARS[]. > > Zeev But also remove one of the single most convenient features of php. Having two namespaces... $var and %var for instance would keep that very very convenient features and also solve the problem. Orion

« previous php.dev (#61003) next »