Re: Security Issues

From: Date: Thu, 26 Jul 2001 10:25:23 +0000
Subject: Re: Security Issues
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-61047@lists.php.net to get a copy of this message
"Zeev Suraski" <zeev@zend.com> wrote in message news:5.1.0.14.2.20010725181631.0690eff8@localhost... > As I said, it's easy, but it is considerably less easy than it is to add > GET variables. Let alone the fact that we're also dealing with SERVER and > ENV vars, which cannot be injected at all. How about people who check > server variables, such as HTTPS, using isset()? register_globals *is* evil. I think register_globals should be set to off for all PHP users. $HTTP_*_VARS are easy enough to access variables. (I would like to see $__POST, $__GET, etc soon, though) Users tends to use "php.ini-dist", since install manual/instruction says "copy php.ini-dist to php.ini". How about provide a "php.ini-recommended" with appropriate comments in next rerelase? Yasuo Ohgaki

« previous php.dev (#61047) next »