Re: Security Issues
| From: | Zeev Suraski | Date: | Thu, 26 Jul 2001 01:33:51 +0000 |
| Subject: | Re: Security Issues | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61018@lists.php.net to get a copy of this message | ||
No obscure %$!@*% variables was one of our main design goals in PHP, only $ for denoting variables. This one is here to stay :)
At 14:58 25/07/2001, PHP wrote:
On Tue, Jul 24, 2001 at 08:27:21PM -0700, Zeev Suraski wrote: Setting register_globals to off (which is highly recommended) would prevent PHP from defining form variables as global variables. For quite a while, since the PHP 3.0 times, PHP provided an alternative way of accessing variables - using special designated arrays - $HTTP_POST_VARS, $HTTP_GET_VARS, and so forth. As of PHP 4.0.3 (IIRC), these variables are always defined, and are protected (to a degree) by PHP. Setting register_globals to off effectively prevents any outer access to your namespace, outside $HTTP_*_VARS[]. Zeev But also remove one of the single most convenient features of php. Having two namespaces... $var and %var for instance would keep that very very convenient features and also solve the problem.-- Zeev Suraski <zeev@zend.com> CTO & co-founder, Zend Technologies Ltd. http://www.zend.com/Orion