Re: Security Issues
| From: | Yasuo Ohgaki | Date: | Thu, 26 Jul 2001 10:25:23 +0000 |
| Subject: | Re: Security Issues | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61047@lists.php.net to get a copy of this message | ||
"Zeev Suraski" <zeev@zend.com> wrote in message
news:5.1.0.14.2.20010725181631.0690eff8@localhost...
> As I said, it's easy, but it is considerably less easy than it is to add
> GET variables. Let alone the fact that we're also dealing with SERVER and
> ENV vars, which cannot be injected at all. How about people who check
> server variables, such as HTTPS, using isset()? register_globals *is* evil.
I think register_globals should be set to off for all PHP users. $HTTP_*_VARS
are easy enough to access variables. (I would like to see $__POST, $__GET, etc
soon, though)
Users tends to use "php.ini-dist", since install manual/instruction says "copy
php.ini-dist to php.ini". How about provide a "php.ini-recommended" with
appropriate comments in next rerelase?
Yasuo Ohgaki