Re: Security Issues

From: Date: Fri, 27 Jul 2001 10:15:12 +0000
Subject: Re: Security Issues
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-61180@lists.php.net to get a copy of this message
* Rasmus Lerdorf wrote: > significantly more secure PHP scripts out there. It will simply cause > scripts to break in non-obvious ways and the knee-jerk fix will be to > swear at those annoying PHP folks and then turn register_globals on, or > they will do something like: > > foreach($HTTP_POST_VARS as $key=>$val) $$key = $val; > foreach($HTTP_GET_VARS as $key=>$val) $$key = $val; > foreach($HTTP_COOKIE_VARS as $key=>$val) $$key = $val; I fully agree here with Rasmus and I also think this will be the workaround for most people -- if one _does_ care about security, he even knows what and how to do nowadays. I don't think turning register_globals to off will evangelize people to develop more secure scripts/applications. -- PHP Schulungen und | International PHP Conference Schulungsmaterial: | 05. - 07.11.2001 http://thinkphp.de/ | Astron Hotel, Frankfurt http://rent-a-phpwizard.de/schulungen.php | http://www.php-kongress.de/

« previous php.dev (#61180) next »